CVE-2007-0115
Summary
| CVE | CVE-2007-0115 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-01-09 02:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php. |
Risk And Classification
Primary CVSS: v2.0 6 from [email protected]
AV:N/AC:M/Au:S/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Coppermine | Coppermine Photo Gallery | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [VIM] Source verify - Coppermine Photo Gallery <= 1.4.10 code injection | af854a3a-2127-422b-91ae-364da2661108 | www.attrition.org | Exploit |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| new.fr is available for purchase - Sedo.com | af854a3a-2127-422b-91ae-364da2661108 | acid-root.new.fr | Exploit |
| Coppermine Photo Gallery <= 1.4.10 SQL Injection Exploit - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| osvdb.org/33383 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.