Coppermine Photo Gallery vulnerabilities
34 known vulnerabilities affecting coppermine/coppermine_photo_gallery.
Total CVEs
34
CISA KEV
0
Public exploits
16
Exploited in wild
1
Severity breakdown
HIGH13MEDIUM19LOW2
Vulnerabilities
Page 2 of 2
CVE-2006-2514HIGHCVSS 7.5≤ 1.4.5v1.0_rc3+12 more2006-05-22
CVE-2006-2514 [HIGH] CVE-2006-2514: Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote att
Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
nvd
CVE-2006-1909MEDIUMCVSS 5.0PoCv1.4.42006-04-20
CVE-2006-1909 [MEDIUM] CVE-2006-1909: Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read a
Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard "../" sequences.
nvd
CVE-2006-0873MEDIUMCVSS 5.0v1.4.32006-02-24
CVE-2006-0873 [MEDIUM] CVE-2006-0873: Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and ear
Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share pathnames.
nvd
CVE-2006-0872MEDIUMCVSS 5.0v1.4.32006-02-24
CVE-2006-0872 [MEDIUM] CVE-2006-0872: Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allo
Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the lang parameter.
nvd
CVE-2005-2676MEDIUMCVSS 4.3v1.0_rc3v1.1_.0+7 more2005-08-23
CVE-2005-2676 [MEDIUM] CVE-2005-2676: Cross-site scripting (XSS) vulnerability in displayimage.php in Coppermine Photo Gallery before 1.3.
Cross-site scripting (XSS) vulnerability in displayimage.php in Coppermine Photo Gallery before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via EXIF data.
nvd
CVE-2005-1225HIGHCVSS 7.5v1.3.22005-05-02
CVE-2005-1225 [HIGH] CVE-2005-1225: SQL injection vulnerability in Coppermine Photo Gallery 1.3.2 allows remote attackers to execute arb
SQL injection vulnerability in Coppermine Photo Gallery 1.3.2 allows remote attackers to execute arbitrary SQL commands via the favs parameter to (1) init.inc.php or (2) zipdownload.php.
nvd
CVE-2005-1226HIGHCVSS 7.5v1.3.22005-05-02
CVE-2005-1226 [HIGH] CVE-2005-1226: Coppermine Photo Gallery 1.3.2 stores passwords in plaintext, which allows remote attackers to obtai
Coppermine Photo Gallery 1.3.2 stores passwords in plaintext, which allows remote attackers to obtain sensitive information.
nvd
CVE-2005-1172MEDIUMCVSS 4.3v1.0_rc3v1.1_.0+5 more2005-05-02
CVE-2005-1172 [MEDIUM] CVE-2005-1172: Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows re
Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.
nvd
CVE-2004-1984MEDIUMCVSS 5.0v1.0_rc3v1.1_.0+4 more2004-05-02
CVE-2004-1984 [MEDIUM] CVE-2004-1984: Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive informatio
Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message.
nvd
CVE-2004-1987HIGHCVSS 7.5v1.0_rc3v1.1_.0+4 more2004-04-30
CVE-2004-1987 [HIGH] CVE-2004-1987: picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with a
picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters.
nvd
CVE-2004-1989HIGHCVSS 7.5PoCv1.0_rc3v1.1_.0+4 more2004-04-30
CVE-2004-1989 [HIGH] CVE-2004-1989: PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remot
PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.
nvd
CVE-2004-1988HIGHCVSS 7.5PoCv1.0_rc3v1.1_.0+4 more2004-04-30
CVE-2004-1988 [HIGH] CVE-2004-1988: PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows
PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.
nvd
CVE-2004-1985MEDIUMCVSS 4.3PoCv1.0_rc3v1.1_.0+4 more2004-04-30
CVE-2004-1985 [MEDIUM] CVE-2004-1985: Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows r
Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.
nvd
CVE-2004-1986MEDIUMCVSS 5.0PoCv1.0_rc3v1.1_.0+4 more2004-04-04
CVE-2004-1986 [MEDIUM] CVE-2004-1986: Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 al
Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.
nvd
← Previous2 / 2