| OSVDB ID | Disclosure Date | Title |
|
23347
Description:
(Description Provided by CVE) : Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share pathnames.
|
2006-02-17
|
Coppermine Photo Gallery showdoc.php f Parameter Local File Inclusion
|
|
5912
Description:
Coppermine Photo Gallery contains a flaw that may allow a remote attacker to execute arbitrary code. The issue is triggered when sending a specially crafted URL request to the theme.php script using the THEME_DIR variable to specify a malicious file from a remote system as a parameter. It is possible that the flaw may allow arbitrary code execution resulting in a loss of integrity.
|
2004-04-29
|
Coppermine Photo Gallery theme.php Multiple Parameter Remote File Inclusion
|
|
47353
Description:
(Description Provided by CVE) : themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
|
2008-07-31
|
Coppermine Photo Gallery themes/sample/theme.php Direct Request Error Message Path Disclosure
|
|
33133
Description:
(Description Provided by CVE) : SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie. NOTE: it was later reported that 1.4.10, 1.4.14, and other 1.4.x versions are also affected using similar cookies.
|
2007-02-24
|
Coppermine Photo Gallery thumbnails.php cpg131_fav Cookie Parameter SQL Injection
|
|
54581
Description:
Coppermine Photo Gallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'thumbnails.php' script not properly sanitizing user-supplied input to the 'GLOBALS[cat]' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database.
|
2009-05-18
|
Coppermine Photo Gallery thumbnails.php GLOBALS[cat] Parameter SQL Injection
|
|
57288
Description:
Coppermine Photo Gallery contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to an unspecified script not properly sanitizing user input supplied to unspecified parameter(s). This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2008-08-06
|
Coppermine Photo Gallery Unspecified Remote File Inclusion
|
|
57295
Description:
Unknown / Incomplete
|
2008-08-06
|
Coppermine Photo Gallery Unspecified Shell Injection Issue
|
|
57291
Description:
Unknown / Incomplete
|
2008-08-06
|
Coppermine Photo Gallery Unspecified SQL Injection
|
|
73128
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.4.27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
2010-05-20
|
Coppermine Photo Gallery Unspecified XSS (2010-4667)
|
|
73129
Description:
(Description Provided by CVE) : Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-4667.
|
2011-01-02
|
Coppermine Photo Gallery Unspecified XSS (2011-2476)
|
|
57915
Description:
(Description Provided by CVE) : Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as the database table prefix via a direct request. NOTE: this might be leveraged for attacks against CVE-2008-0504.
|
2008-01-31
|
Coppermine Photo Gallery update.php Direct Request Information Disclosure
|
|
44345
Description:
(Description Provided by CVE) : SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is used for an upload.
|
2008-04-11
|
Coppermine Photo Gallery upload.php Content-Type HTTP Header SQL Injection
|
|
62261
Description:
Coppermine Photo Gallery contains a flaw that allows a remote cross site scripting (XSS) attack. This flaw exists because the application does not validate the URL upon submission to the upload.php script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
|
2010-01-28
|
Coppermine Photo Gallery upload.php URI XSS
|
|
35853
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.
|
2007-01-04
|
Coppermine Photo Gallery usermgr.php gid Parameter SQL Injection
|
|
26211
Description:
(Description Provided by CVE) : Unspecified vulnerability in usermgr.php in Coppermine Photo Gallery before 1.4.7 has unknown impact and remote attack vectors, possibly related to authorization/authentication errors.
|
2006-06-06
|
Coppermine Photo Gallery usermgr.php Unspecified Issue
|
|
41678
Description:
(Description Provided by CVE) : Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authen ticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php.
|
2008-01-29
|
Coppermine Photo Gallery util.php Unspecified SQL Injection
|
|
37101
Description:
(Description Provided by CVE) : Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log parameter.
|
2007-09-18
|
Coppermine Photo Gallery viewlog.php log Parameter Local File Inclusion
|
|
10855
Description:
Coppermine Photo Gallery contains a flaw that may allow a remote attacker to arbitrary manipulate votings. The issue is triggered due the gallery relying on browser cookies to restrict voting. If cookies are turned on and a user votes, they will not be able to vote a second time. However, if the user disables cookies in their browser, Coppermine will allow them to vote as many times as they want.
|
2004-10-12
|
Coppermine Photo Gallery Voting Restriction Bypass
|
|
15882
Description:
Unknown / Incomplete
|
2004-04-20
|
Coppermine Photo Gallery zipdownload.php Arbitrary File Access
|
|
50908
Description:
Coppermine Photo Gallery contains a flaw that may allow an attacker to carry out an SQL injection attack. The issue is due to the 'zipdownload.php' script not properly sanitizing user-supplied input to the 'favs' parameter. This may allow an attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.
|
2005-04-20
|
Coppermine Photo Gallery zipdownload.php favs Parameter SQL Injection
|
|
3145
Description:
COPS Security Checker contains a flaw that allows local attackers to overwrite arbitrary files and possibly gain root priveleges. The flaw is due to a lack of sanity checking on calls to temporary files created in /tmp that do not check for existing files with the same name. Such flaws can be taken advantage of with symlinks and arbitrary files can be overwritten or appended to.
|
1998-06-28
|
COPS Temporary File Race Condition and Symlink
|
|
16720
Description:
Unknown / Incomplete
|
2005-05-16
|
CORE CMS Multiple Unspecified Issues
|
|
72938
Description:
Core Design Scriptegrator Plugin for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the plugins/system/cdscriptegrator/libraries/highslide/css/cssloader.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'files[]' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2011-06-13
|
Core Design Scriptegrator Plugin for Joomla! plugins/system/cdscriptegrator/libraries/highslide/css/cssloader.php files[] Parameter Traversal Local File Inclusion
|
|
62406
Description:
Core Design Scriptegrator Plugin for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php' script not properly sanitizing user input supplied to the 'files[]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-02-18
|
Core Design Scriptegrator Plugin for Joomla! plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php files[] Parameter Remote File Inclusion
|
|
62485
Description:
Core Design Scriptegrator Plugin for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'plugins/system/cdscriptegrator/libraries/jquery/js/jsloader.php' script not properly sanitizing user input supplied to the 'files[]' parameter. This may allow an attacker to include a file from a third-party remote host that contains commands or code that will be executed by the vulnerable script with the same privileges as the web server.
|
2010-02-18
|
Core Design Scriptegrator Plugin for Joomla! plugins/system/cdscriptegrator/libraries/jquery/js/jsloader.php files[] Parameter Remote File Inclusion
|
|
62484
Description:
Core Design Scriptegrator Plugin contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the 'plugins/system/cdscriptegrator/libraries/jquery/js/ui/jsloader.php' script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'file' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2010-02-18
|
Core Design Scriptegrator Plugin for Joomla! plugins/system/cdscriptegrator/libraries/jquery/js/ui/jsloader.php file Parameter Traversal Local File Inclusion
|
|
72939
Description:
Core Design Scriptegrator Plugin for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the plugins/system/cdscriptegrator/libraries/jquery/theme/cssloader.php script not properly sanitizing user input, specifically directory traversal style attacks (e.g., ../../) supplied to the 'file' parameter. This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2011-06-13
|
Core Design Scriptegrator Plugin for Joomla! plugins/system/cdscriptegrator/libraries/jquery/theme/cssloader.php file ParameterTraversal Local File Inclusion
|
|
73205
Description:
Core Design Scriptegrator Plugin for Joomla! contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to unspecified input not being properly sanitized before being returned to the user, specifically directory traversal style attacks (e.g., ../../). This may allow an attacker to include a file from the targeted host that contains arbitrary commands or code that will be executed by the vulnerable script. Such attacks are limited due to the script only calling files already on the target host. In addition, this flaw can potentially be used to disclose the contents of any file on the system accessible by the web server.
|
2011-06-17
|
Core Design Scriptegrator Plugin for Joomla! Unspecified Traversal Local File Inclusion
|
|
43256
Description:
(Description Provided by CVE) : Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.
|
2008-01-17
|
CORE FORCE Firewall Module IOCTL Functions Multiple Local Overflows
|
|
43257
Description:
(Description Provided by CVE) : Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.
|
2008-01-17
|
CORE FORCE Registry Module SSDT Hook Handler Functions Multiple Local Overflows
|