vendor:
Coppermine Photo Gallery
by:
Michael Brooks
7.5
CVSS
HIGH
Bypassing register_globals security
16
CWE
Product Name: Coppermine Photo Gallery
Affected Version From: 1.4.19
Affected Version To: 1.4.19
Patch Exists: YES
Related CWE: N/A
CPE: a:coppermine-gallery:coppermine_photo_gallery
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Coppermine Photo gallery – Remote PHP File Upload
The Coppermine Photo Gallery is vulnerable to a remote PHP file upload vulnerability due to a bypass of the anti-register_globals security. This vulnerability allows an attacker to upload malicious PHP files to the server, which can be used to gain access to the server. The vulnerability is present in version 1.4.19 of the Coppermine Photo Gallery and can be exploited by setting the register_globals parameter to 'on'. A patch is available to fix the vulnerability by unsetting all variables except for the superglobals.
Mitigation:
Upgrade to the latest version of Coppermine Photo Gallery and apply the patch to fix the vulnerability.