Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-3558SQL Injection in Photo Gallery

4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.9%
top 23.87%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 4
Latest updateMay 1

Description

SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary SQL commands via an album password cookie to an unspecified component.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p2wf-r9mv-p43x: SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 12022-05-01
CVEList
CVE-2007-3558: SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 12007-07-04

💥Exploits & PoCs

1
Exploit-DB
Coppermine Photo Gallery 1.4.10 - 'xpl.php' SQL Injection2007-01-05
CVE-2007-3558 — SQL Injection in Photo Gallery | cvebase