{"api_version":"1","generated_at":"2026-07-23T06:56:22+00:00","cve":"CVE-2008-0506","urls":{"html":"https://cve.report/CVE-2008-0506","api":"https://cve.report/api/cve/CVE-2008-0506.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0506","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0506"},"summary":{"title":"CVE-2008-0506","description":"include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-01-31 20:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://coppermine-gallery.net/forum/index.php?topic=50103.0","name":"http://coppermine-gallery.net/forum/index.php?topic=50103.0","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28682","name":"http://secunia.com/advisories/28682","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Coppermine Photo Gallery Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1019286","name":"http://www.securitytracker.com/id?1019286","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Coppermine Photo Gallery Input Validation Flaw in 'imageObjectIM' Lets Remote Users Execute Arbitrary Commands","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/5019","name":"https://www.exploit-db.com/exploits/5019","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Coppermine Photo Gallery 1.4.14 Remote Command Execution Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0367","name":"http://www.vupen.com/english/advisories/2008/0367","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/27512","name":"http://www.securityfocus.com/bid/27512","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch"],"title":"Coppermine Photo Gallery Multiple Remote Command Execution Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.waraxe.us/advisory-65.html","name":"http://www.waraxe.us/advisory-65.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[waraxe-2008-SA#065] - Remote Shell Command Execution in Coppermine 1.4.14","mime":"text/html","httpstatus":"200","archivestatus":"504"},{"url":"http://www.securityfocus.com/archive/1/487310/100/200/threaded","name":"http://www.securityfocus.com/archive/1/487310/100/200/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0506","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0506","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"506","vulnerable":"1","versionEndIncluding":"1.4.14","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"coppermine","cpe5":"coppermine_photo_gallery","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T07:46:55.013Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.waraxe.us/advisory-65.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://coppermine-gallery.net/forum/index.php?topic=50103.0"},{"name":"ADV-2008-0367","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0367"},{"name":"27512","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27512"},{"name":"28682","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28682"},{"name":"20080130 [waraxe-2008-SA#065] - Remote Shell Command Execution in Coppermine 1.4.14","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/487310/100/200/threaded"},{"name":"1019286","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1019286"},{"name":"5019","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/5019"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-01-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.waraxe.us/advisory-65.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://coppermine-gallery.net/forum/index.php?topic=50103.0"},{"name":"ADV-2008-0367","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0367"},{"name":"27512","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27512"},{"name":"28682","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28682"},{"name":"20080130 [waraxe-2008-SA#065] - Remote Shell Command Execution in Coppermine 1.4.14","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/487310/100/200/threaded"},{"name":"1019286","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1019286"},{"name":"5019","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/5019"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-0506","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.waraxe.us/advisory-65.html","refsource":"MISC","url":"http://www.waraxe.us/advisory-65.html"},{"name":"http://coppermine-gallery.net/forum/index.php?topic=50103.0","refsource":"CONFIRM","url":"http://coppermine-gallery.net/forum/index.php?topic=50103.0"},{"name":"ADV-2008-0367","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0367"},{"name":"27512","refsource":"BID","url":"http://www.securityfocus.com/bid/27512"},{"name":"28682","refsource":"SECUNIA","url":"http://secunia.com/advisories/28682"},{"name":"20080130 [waraxe-2008-SA#065] - Remote Shell Command Execution in Coppermine 1.4.14","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/487310/100/200/threaded"},{"name":"1019286","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1019286"},{"name":"5019","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/5019"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0506","datePublished":"2008-01-31T19:30:00.000Z","dateReserved":"2008-01-31T00:00:00.000Z","dateUpdated":"2024-08-07T07:46:55.013Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-01-31 20:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:coppermine:coppermine_photo_gallery:*:*:*:*:*:*:*:*","versionEndIncluding":"1.4.14","matchCriteriaId":"95F6AC5A-EA42-4B35-891A-C42527F29C67"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"506","Ordinal":"1","Title":"CVE-2008-0506","CVE":"CVE-2008-0506","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"506","Ordinal":"1","NoteData":"include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.","Type":"Description","Title":"CVE-2008-0506"},{"CveYear":"2008","CveId":"506","Ordinal":"2","NoteData":"2008-01-31","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"506","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}