Vulnerabilities > CVE-2007-0122 - SQL Injection vulnerability in Coppermine Photo Gallery Albmgr.PHP

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
coppermine
exploit available

Summary

Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.

Exploit-Db

  • descriptionCoppermine Photo Gallery 1.x Albmgr.PHP SQL Injection Vulnerability. CVE-2007-0122. Webapps exploit for php platform
    idEDB-ID:29397
    last seen2016-02-03
    modified2007-01-05
    published2007-01-05
    reporterDarkFig
    sourcehttps://www.exploit-db.com/download/29397/
    titleCoppermine Photo Gallery 1.x Albmgr.PHP SQL Injection Vulnerability
  • idEDB-ID:3085