CVE-2006-3064
SQL injection vulnerability in the add_hit function in include/function.inc.php in Coppermine Photo Gallery (CPG) 1.4.8, when "Keep detailed hit statistics" is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) referer and…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in the add_hit function in include/function.inc.php in Coppermine Photo Gallery (CPG) 1.4.8, when "Keep detailed hit statistics" is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) referer and (2) user-agent HTTP headers.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- coppermine/coppermine photo gallery
- Source
- cve@mitre.org
References
- http://myimei.com/security/2006-06-11/copperminephotogallery148-addhit-function-sqlinjection-attack.htmlExploit
- http://secunia.com/advisories/20597Vendor Advisory
- http://www.securityfocus.com/archive/1/436799/30/4470/threaded
- http://www.vupen.com/english/advisories/2006/2317Vendor Advisory
- http://myimei.com/security/2006-06-11/copperminephotogallery148-addhit-function-sqlinjection-attack.htmlExploit
- http://secunia.com/advisories/20597Vendor Advisory
- http://www.securityfocus.com/archive/1/436799/30/4470/threaded
- http://www.vupen.com/english/advisories/2006/2317Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.