vendor:
Coppermine Photo Gallery
by:
Disfigure, Synsta, [w4ck1ng]
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Coppermine Photo Gallery
Affected Version From: 1.4.9
Affected Version To: 1.4.9
Patch Exists: YES
Related CWE: N/A
CPE: a:coppermine:coppermine_photo_gallery
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Coppermine Photo Gallery 1.4.9 Remote SQL Injection Vulnerability
This exploit allows an attacker to gain access to the Coppermine Photo Gallery 1.4.9 application by exploiting a Remote SQL Injection vulnerability. The attacker needs a valid user account to exploit this vulnerability. The exploit requires the host, path, table prefix, user id, username and password as parameters. The exploit uses the 'albmgr.php' script to inject a malicious SQL query and extract the user's password.
Mitigation:
Upgrade to the latest version of Coppermine Photo Gallery and ensure that all user input is properly sanitized.