CVE-2004-1987
published 2004-04-30CVE-2004-1987: picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
10.20%
95.1th percentile
picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coppermine | coppermine_photo_gallery | — | — |
| coppermine | coppermine_photo_gallery | — | — |
| coppermine | coppermine_photo_gallery | — | — |
| coppermine | coppermine_photo_gallery | — | — |
| coppermine | coppermine_photo_gallery | — | — |
| coppermine | coppermine_photo_gallery | — | — |
| francisco_burzi | php-nuke | — | — |
| francisco_burzi | php-nuke | — | — |
| francisco_burzi | php-nuke | — | — |
| francisco_burzi | php-nuke | — | — |
| francisco_burzi | php-nuke | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=108360247732014&w=2http://secunia.com/advisories/11524http://securitytracker.com/id?1010001http://www.osvdb.org/5759http://www.securityfocus.com/bid/10253http://www.waraxe.us/index.php?modname=sa&id=26https://exchange.xforce.ibmcloud.com/vulnerabilities/16043http://marc.info/?l=bugtraq&m=108360247732014&w=2http://secunia.com/advisories/11524http://securitytracker.com/id?1010001http://www.osvdb.org/5759http://www.securityfocus.com/bid/10253http://www.waraxe.us/index.php?modname=sa&id=26https://exchange.xforce.ibmcloud.com/vulnerabilities/16043
2004-04-30
Published