CVE-2008-0506
include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle,…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 58.9%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 58.90% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- coppermine/coppermine photo gallery
- Source
- cve@mitre.org
References
- http://coppermine-gallery.net/forum/index.php?topic=50103.0Patch
- http://secunia.com/advisories/28682Vendor Advisory
- http://www.securityfocus.com/archive/1/487310/100/200/threaded
- http://www.securityfocus.com/bid/27512Exploit, Patch
- http://www.securitytracker.com/id?1019286
- http://www.vupen.com/english/advisories/2008/0367Vendor Advisory
- http://www.waraxe.us/advisory-65.html
- https://www.exploit-db.com/exploits/5019
- http://coppermine-gallery.net/forum/index.php?topic=50103.0Patch
- http://secunia.com/advisories/28682Vendor Advisory
- http://www.securityfocus.com/archive/1/487310/100/200/threaded
- http://www.securityfocus.com/bid/27512Exploit, Patch
- http://www.securitytracker.com/id?1019286
- http://www.vupen.com/english/advisories/2008/0367Vendor Advisory
- http://www.waraxe.us/advisory-65.html
- https://www.exploit-db.com/exploits/5019
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.