Skip to main content

Vendor/product archive

coppermine / coppermine_photo_gallery CVEs

Beta · best-effort

35 CVEs tagged to coppermine / coppermine_photo_gallery1 Critical, 13 High, 19 Medium, 2 Low, 0 Unrated.

CVE-2009-1616

Published May 11, 2009

Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1840

Published Apr 16, 2008

SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute ar…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1841

Published Apr 16, 2008

SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to exec…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0505

Published Jan 31, 2008

Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0506

Published Jan 31, 2008

include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5888

Published Nov 7, 2007

Cross-site scripting (XSS) vulnerability in displayecard.php in Coppermine Photo Gallery (CPG) before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4976

Published Sep 19, 2007

Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary l…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4977

Published Sep 19, 2007

Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the re…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-4283

Published Aug 9, 2007

PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the sou…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3558

Published Jul 4, 2007

SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary SQL commands via an album password cookie to an unspecifie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1414

Published Mar 12, 2007

Multiple PHP remote file inclusion vulnerabilities in Coppermine Photo Gallery (CPG) allow remote attackers to execute arbitrary PHP code via a URL in the (1) cmd parameter to (a)…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1107

Published Feb 26, 2007

SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0835

Published Feb 8, 2007

admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to execute arbitrary shell commands via shell metacharacters (";" semicolon)…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0836

Published Feb 8, 2007

admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote files via the (1) "Path to cus…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0115

Published Jan 9, 2007

Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to log…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0122

Published Jan 9, 2007

Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat p…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6123

Published Nov 26, 2006

Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals enabled, allows remote attackers to bypass XSS protection and set arbitrary variables via a query string that ca…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-5622

Published Oct 31, 2006

SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary SQL commands via the aid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4321

Published Aug 24, 2006

PHP remote file inclusion vulnerability in cpg.php in the Coppermine Photo Gallery component (com_cpg) 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3064

Published Jun 19, 2006

SQL injection vulnerability in the add_hit function in include/function.inc.php in Coppermine Photo Gallery (CPG) 1.4.8, when "Keep detailed hit statistics" is enabled, allows rem…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2976

Published Jun 12, 2006

Unspecified vulnerability in usermgr.php in Coppermine Photo Gallery before 1.4.7 has unknown impact and remote attack vectors, possibly related to authorization/authentication er…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2514

Published May 22, 2006

Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-1909

Published Apr 20, 2006

Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, whic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0872

Published Feb 24, 2006

Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0873

Published Feb 24, 2006

Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, an…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 35 CVEsPage 1 of 2