| OSVDB ID | Disclosure Date | Title |
|
35068
Description:
Coppermine Photo Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to include/plugin_api.inc.php not properly sanitizing user input supplied to the path variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2007-03-09
|
Coppermine Photo Gallery include/plugin_api.inc.php path Parameter Remote File Inclusion
|
|
57916
Description:
(Description Provided by CVE) : Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, which leaks the installation path in an error message.
|
2008-01-31
|
Coppermine Photo Gallery include/slideshow.inc.php Direct Request Path Disclosure
|
|
24744
Description:
(Description Provided by CVE) : Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard "../" sequences.
|
2006-04-14
|
Coppermine Photo Gallery index.php file Parameter Traversal Local File Inclusion
|
|
54582
Description:
Coppermine Photo Gallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the thumbnails.php script not properly sanitizing user-supplied input to the GLOBALS[USER][lang] and GLOBALS[cat] parameters. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-05-18
|
Coppermine Photo Gallery index.php GLOBALS[USER][lang] Parameter Traversal Local File Inclusion
|
|
35069
Description:
Coppermine Photo Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to index.php not properly sanitizing user input supplied to the 'path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2007-03-09
|
Coppermine Photo Gallery index.php path Parameter Remote File Inclusion
|
|
50907
Description:
Coppermine Photo Gallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'init.inc.php' script not properly sanitizing user-supplied input to the 'favs' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2005-04-20
|
Coppermine Photo Gallery init.inc.php favs Parameter SQL Injection
|
|
15672
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.
|
2005-04-18
|
Coppermine Photo Gallery init.inc.php HTTP_X_FORWARDED_FOR XSS
|
|
23346
Description:
Coppermine Photo Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to init.inc.php script not properly sanitizing user input supplied to the 'lang' variable. This may allow an attacker to include a file from a local system via the thumbnails.php script that contains arbitrary commands which will be executed by the vulnerable script.
|
2006-02-17
|
Coppermine Photo Gallery init.inc.php lang Parameter Local File Inclusion
|
|
27618
Description:
CPG (Coppermine Photo Gallery) contains a flaw that may allow a malicious user to bypass input validation safe guards. There is a flaw in the design of the input validation process that may allow an attacker to erase some global variables (_GET, _REQUEST, _POST ...). For example, the 'MyVar' variable can be set globally to an arbitrary value because the input validation scheme fails when the _GET and _REQUEST variables are erased.
|
2006-06-20
|
Coppermine Photo Gallery init.inc.php Parameter Cleanup XSS Protection Bypass
|
|
5761
Description:
Coppermine Photo Gallery contains a flaw that may allow a remote attacker to execute arbitrary code. The issue is triggered when sending a specially crafted URL request to the init.inc.php script using the CPG_M_DIR variable to specify a malicious file from a remote system as a parameter. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2004-04-29
|
Coppermine Photo Gallery init.inc.php Remote File Inclusion
|
|
15880
Description:
Coppermine Photo Gallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'init.inc.php' script not properly sanitizing user-supplied input to the 'thecookie' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2004-04-20
|
Coppermine Photo Gallery init.inc.php thecookie Parameter SQL Injection
|
|
57287
Description:
Unknown / Incomplete
|
2008-08-06
|
Coppermine Photo Gallery Language Selector XSS
|
|
33383
Description:
(Description Provided by CVE) : Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php.
|
2007-01-05
|
Coppermine Photo Gallery login.php Username Parameter SQL Injection
|
|
5757
Description:
Coppermine Photo Gallery contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the "CPG_URL" variable upon submission to the menu.inc.php script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
|
2004-04-29
|
Coppermine Photo Gallery menu.inc.php CPG_URL Parameter XSS
|
|
37100
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the referer parameter.
|
2007-09-18
|
Coppermine Photo Gallery mode.php referer Parameter XSS
|
|
5758
Description:
Coppermine Photo Gallery contains a flaw that allows a remote attacker to view arbitrary files outside of the web path. The issue is due to the 'modules.php' script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'startdir' variable.
|
2004-04-29
|
Coppermine Photo Gallery modules.php startdir Parameter Traversal Arbitrary File Access
|
|
50624
Description:
Unknown / Incomplete
|
2003-04-07
|
Coppermine Photo Gallery Multiple Extension File Upload Arbitrary PHP Code Execution
|
|
72883
Description:
Coppermine Photo Gallery contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when a remote attacker sends a direct request to the /plugins/link_target/configuration.php, /plugins/opensearch/configuration.php or /plugins/onlinestats/index.php scripts, which discloses the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
|
2011-02-17
|
Coppermine Photo Gallery Multiple Script Direct Request Path Disclosure
|
|
57294
Description:
Unknown / Incomplete
|
2008-08-06
|
Coppermine Photo Gallery Multiple Unspecified Issues
|
|
39251
Description:
(Description Provided by CVE) : Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
|
2006-05-22
|
Coppermine Photo Gallery on Apache Multiple File Extension Arbitrary File Upload
|
|
5756
Description:
Coppermine Photo Gallery contains a flaw that may lead to an unauthorized information disclosure. By sending specially crafted URL requests to the phpinfo.php script the program will return an error message, which will disclose the installation path resulting in a loss of confidentiality.
|
2004-04-29
|
Coppermine Photo Gallery phpinfo.php Path Disclosure
|
|
73130
Description:
Unknown / Incomplete
|
2011-02-08
|
Coppermine Photo Gallery picmgmt.inc.php Remote Command Execution
|
|
5759
Description:
Coppermine Photo Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands. By supplying specially crafted "impath" or "jpeg_equal" configuration parameters, a remote attacker could execute arbitrary shell commands on the system, resulting in a loss of integrity.
|
2004-04-29
|
Coppermine Photo Gallery picmgmtbatch.inc.php Arbitrary Command Execution
|
|
30097
Description:
(Description Provided by CVE) : SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary SQL commands via the aid parameter.
|
2006-10-27
|
Coppermine Photo Gallery picmgr.php aid Parameter SQL Injection
|
|
35070
Description:
Coppermine Photo Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to pluginmgr.php not properly sanitizing user input supplied to the 'path' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.
|
2007-03-09
|
Coppermine Photo Gallery pluginmgr.php path Parameter Remote File Inclusion
|
|
57292
Description:
Unknown / Incomplete
|
2008-08-06
|
Coppermine Photo Gallery referer Header Manipulation Unspecified Issue
|
|
21381
Description:
(Description Provided by CVE) : relocate_server.php in Coppermine Photo Gallery (CPG) 1.4.2 and 1.4 beta does not remove is not removed after installation and does not use authentication, which allows remote attackers to obtain sensitive information, such as database configuration, via a direct request.
|
2005-11-27
|
Coppermine Photo Gallery relocate_server.php Information Disclosure
|
|
41679
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authen ticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php.
|
2008-01-29
|
Coppermine Photo Gallery reviewcom.php Unspecified SQL Injection
|
|
57290
Description:
Unknown / Incomplete
|
2008-08-06
|
Coppermine Photo Gallery Search Logic Unspecified Issue
|
|
70174
Description:
Coppermine Photo Gallery contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified data upon submission to the searchnew.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-12-28
|
Coppermine Photo Gallery searchnew.php picfile_* Parameter XSS
|