6.8
CVSSv2

CVE-2008-1841

Published: 16/04/2008 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and previous versions allows remote malicious users to execute arbitrary SQL commands via an input field associated with the session_id variable, as exploited in the wild in April 2008. NOTE: the fix for CVE-2008-1840 was intended to address this vulnerability, but is actually inapplicable.

Vulnerable Product Search on Vulmon Subscribe to Product

coppermine coppermine photo gallery 1.4.17

coppermine coppermine photo gallery 1.4.8

coppermine coppermine photo gallery 1.4.11

coppermine coppermine photo gallery 1.4.12

coppermine coppermine photo gallery 1.3.0

coppermine coppermine photo gallery 1.4.13

coppermine coppermine photo gallery 1.3.1

coppermine coppermine photo gallery 1.3.2

coppermine coppermine photo gallery 1.4.7

coppermine coppermine photo gallery 1.4.2

coppermine coppermine photo gallery 1.4.5

coppermine coppermine photo gallery 1.4.6

coppermine coppermine photo gallery 1.4.9

coppermine coppermine photo gallery 1.3.5

coppermine coppermine photo gallery 1.4.16

coppermine coppermine photo gallery 1.2.0rc2

coppermine coppermine photo gallery 1.4.4

coppermine coppermine photo gallery 1.4.14

coppermine coppermine photo gallery 1.2.0

coppermine coppermine photo gallery 1.2.1

coppermine coppermine photo gallery 1.4.10

coppermine coppermine photo gallery 1.3.3