vendor:
Coppermine
by:
Janek Vind
5.5
CVSS
MEDIUM
Multiple Vulnerabilities
79
CWE
Product Name: Coppermine
Affected Version From: 1.5.18
Affected Version To: 1.5.18
Patch Exists: NO
Related CWE:
CPE: a:coppermine_gallery:coppermine:1.5.18
Platforms Tested:
2012
[waraxe-2012-SA#081] – Multiple Vulnerabilities in Coppermine 1.5.18
The Coppermine web picture gallery script version 1.5.18 is affected by multiple vulnerabilities. The first vulnerability is a stored cross-site scripting (XSS) in the picture keywords feature. This vulnerability allows an attacker with appropriate privileges to insert malicious code in the keywords field, which is later displayed in the HTML meta section, leading to XSS attacks. The second vulnerability is a path disclosure vulnerability in the "visible" feature of the software. This vulnerability allows an attacker to disclose sensitive information about the file structure of the server.
Mitigation:
To mitigate the stored XSS vulnerability, it is recommended to properly sanitize user-supplied input data before outputting it as HTML. To mitigate the path disclosure vulnerability, it is recommended to validate user input to prevent the disclosure of sensitive information.