📦

coppermine_photo_gallery

Vendor: coppermine-gallery

Actively Exploited 0 CISA KEV List
PoC / Exploits 22 Code Available
Total RCEs 5 Remote Access
Total CVEs 50 Total Indexed
Avg. EPSS 3.84% Exploit Prob.
Latest CVE CVE-2023-53868 Dec 15

Security Vulnerability Index

Page 3 / 5
6.5 CVSS
CVE-2008-0504
Exploit Found

Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php.

EPSS: 1.97%
6.8 CVSS
CVE-2008-0506
RCE Exploit Found

include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.

EPSS: 58.90%
4.3 CVSS

Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters.

EPSS: 1.47%
4.3 CVSS

Cross-site scripting (XSS) vulnerability in displayecard.php in Coppermine Photo Gallery (CPG) before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the data parameter.

EPSS: 1.06%
3.5 CVSS
CVE-2007-4977
Exploit Found

Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the referer parameter.

EPSS: 3.38%
6.5 CVSS
CVE-2007-4976
Exploit Found

Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log parameter.

EPSS: 8.75%
7.5 CVSS
CVE-2007-4283
Exploit Found

PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the sourcedir parameter.

EPSS: 3.07%
7.5 CVSS
CVE-2007-3558
Exploit Found

SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary SQL commands via an album password cookie to an unspecified component.

EPSS: 1.02%
10.0 CVSS

Multiple PHP remote file inclusion vulnerabilities in Coppermine Photo Gallery (CPG) allow remote attackers to execute arbitrary PHP code via a URL in the (1) cmd parameter to (a) image_processor.php or (b) picmgmt.inc.php, or the (2) path parameter to (c) include/functions.php, (d) include/plugin_api.inc.php, (e) index.php, or (f) pluginmgr.php.

EPSS: 5.24%
7.5 CVSS
CVE-2007-1107
Exploit Found

SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie. NOTE: it was later reported that 1.4.10, 1.4.14, and other 1.4.x versions are also affected using similar cookies.

EPSS: 2.13%