CVE-2007-0115

Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:coppermine:coppermine_photo_gallery:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:25

Type Values Removed Values Added
References () http://acid-root.new.fr/poc/19070104.txt - Exploit () http://acid-root.new.fr/poc/19070104.txt - Exploit
References () http://osvdb.org/33383 - () http://osvdb.org/33383 -
References () http://securityreason.com/securityalert/2107 - () http://securityreason.com/securityalert/2107 -
References () http://www.attrition.org/pipermail/vim/2007-January/001218.html - Exploit () http://www.attrition.org/pipermail/vim/2007-January/001218.html - Exploit
References () http://www.securityfocus.com/archive/1/456051/100/0/threaded - () http://www.securityfocus.com/archive/1/456051/100/0/threaded -

Information

Published : 2007-01-09 02:28

Updated : 2024-11-21 00:25


NVD link : CVE-2007-0115

Mitre link : CVE-2007-0115

CVE.ORG link : CVE-2007-0115


JSON object : View

Products Affected

coppermine

  • coppermine_photo_gallery