CVE-2014-4612
Summary
| CVE | CVE-2014-4612 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-16 17:29:00 UTC |
| Updated | 2023-11-07 02:20:00 UTC |
| Description | Cross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5.27 and 1.6.x before 1.6.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Coppermine-gallery | Coppermine Photo Gallery | All | All | All | All |
| Application | Coppermine-gallery | Coppermine Photo Gallery | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Coppermine Photo Gallery / Code / Commit [r8674] | CONFIRM | sourceforge.net | Patch |
| Coppermine Photo Gallery 'keywordmgr.php' Cross Site Scripting Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| forum.coppermine-gallery.net/index.php/topic%2C77376.0.html | forum.coppermine-gallery.net | ||
| Coppermine Photo Gallery / Code / [r8674] /trunk/cpg1.6.x/CHANGELOG.txt | CONFIRM | sourceforge.net | Release Notes |
| oss-sec: Re: CVE request: XSS in coppermine gallery before 1.5.28 | MLIST | seclists.org | Mailing List, Third Party Advisory |
| Coppermine Photo Gallery / Code / [r8674] /trunk/cpg1.5.x/CHANGELOG.txt | CONFIRM | sourceforge.net | Release Notes |
| oss-sec: CVE request: XSS in coppermine gallery before 1.5.28 | MLIST | seclists.org | Mailing List, Patch, Third Party Advisory |
| forum.coppermine-gallery.net/index.php/topic,77376.0.html | CONFIRM | forum.coppermine-gallery.net | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.