CVE-2008-0504
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4)…
Does this matter?
Lower severity and a low EPSS score (1.97%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.97% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- coppermine-gallery/coppermine photo gallery
- Source
- cve@mitre.org
References
- http://coppermine-gallery.net/forum/index.php?topic=50103.0Patch
- http://secunia.com/advisories/28682Vendor Advisory
- http://www.securityfocus.com/archive/1/487351/100/200/threaded
- http://www.securityfocus.com/bid/27509Patch
- http://www.securitytracker.com/id?1019285
- http://www.vupen.com/english/advisories/2008/0367Vendor Advisory
- http://www.waraxe.us/advisory-66.html
- http://coppermine-gallery.net/forum/index.php?topic=50103.0Patch
- http://secunia.com/advisories/28682Vendor Advisory
- http://www.securityfocus.com/archive/1/487351/100/200/threaded
- http://www.securityfocus.com/bid/27509Patch
- http://www.securitytracker.com/id?1019285
- http://www.vupen.com/english/advisories/2008/0367Vendor Advisory
- http://www.waraxe.us/advisory-66.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.