CVE-2007-0836
Coppermine Photo Gallery 1.4.10 - Multiple Local/Remote File Inclusions
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote files via the (1) "Path to custom header include" and (2) "Path to custom footer include" form fields. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
admin.php en Coppermine Photo Gallery 1.4.10 y, posiblemente en versiones anteriores, permite a usuarios remotos autenticados incluir ficheros locales de su elección y, posiblemente, también ficheros remotos mediante (1) "ruta a la inclusión de cabecera personalizada" y (2) "ruta a la inclusión del pie de página personalizado" en los campos de formulario. NOTA: la procedencia de esta información es desconocida; los detalles se obtienen a partir de la información de terceros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2007-02-05 First Exploit
- 2007-02-07 CVE Reserved
- 2007-02-08 CVE Published
- 2023-12-12 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://osvdb.org/33094 | Vdb Entry | |
http://www.securityfocus.com/bid/22409 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/32233 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/29568 | 2007-02-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/24019 | 2017-07-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Coppermine Search vendor "Coppermine" | Coppermine Photo Gallery Search vendor "Coppermine" for product "Coppermine Photo Gallery" | <= 1.4.10 Search vendor "Coppermine" for product "Coppermine Photo Gallery" and version " <= 1.4.10" | - |
Affected
|