Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and...
Vulnerability Description
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-0122
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/35853
- http://securityreason.com/securityalert/2123
- http://secunia.com/advisories/25846
- http://acid-root.new.fr/poc/19070104.txt
- https://www.exploit-db.com/exploits/3085
- http://osvdb.org/35854
- http://osvdb.org/35852
- http://www.securityfocus.com/archive/1/456051/100/0/threaded
- http://www.securityfocus.com/bid/21894
- http://osvdb.org/35856
- http://osvdb.org/35855
More from coppermine
View All →Affected Vendor
coppermine
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.