vendor:
Coppermine Photo Gallery
by:
Juri Gianni aka yeat
7.5
CVSS
HIGH
Privilege Escalation
94
CWE
Product Name: Coppermine Photo Gallery
Affected Version From: 1.4.20
Affected Version To: 1.4.20
Patch Exists: Yes
Related CWE: N/A
CPE: a:coppermine-gallery:coppermine_photo_gallery
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Coppermine Photo Gallery <= 1.4.20 (BBCode IMG) Privilege Escalation PoC
A vulnerability exists in Coppermine Photo Gallery version 1.4.20 and prior that allows an attacker to inject malicious code into a BBCode IMG tag. This can be used to escalate privileges when an administrator visits the page.
Mitigation:
Upgrade to the latest version of Coppermine Photo Gallery.