Coppermine Photo Gallery Albmgr.PHP SQL Injection Vulnerability
BID:21894
Info
Coppermine Photo Gallery Albmgr.PHP SQL Injection Vulnerability
| Bugtraq ID: | 21894 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0122 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 05 2007 12:00AM |
| Updated: | Jul 03 2007 07:18PM |
| Credit: | DarkFig is credited with the discovery of this issue. |
| Vulnerable: |
Coppermine Photo Gallery 1.4.10 Coppermine Photo Gallery 1.4.9 Coppermine Photo Gallery 1.4.4 Coppermine Photo Gallery 1.3.4 Coppermine Photo Gallery 1.3.3 Coppermine Photo Gallery 1.3.2 Coppermine Photo Gallery 1.3 Coppermine Photo Gallery 1.2.2 b-Nuke Coppermine Photo Gallery 1.2.2 b Coppermine Photo Gallery 1.2.1 Coppermine Photo Gallery 1.2 Coppermine Photo Gallery 1.1 beta 2 Coppermine Photo Gallery 1.1 .0 Coppermine Photo Gallery 1.0 RC3 Coppermine Photo Gallery 1.0 |
| Not Vulnerable: |
Coppermine Photo Gallery 1.4.11 |
Discussion
Coppermine Photo Gallery Albmgr.PHP SQL Injection Vulnerability
Coppermine Photo Gallery is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Coppermine Photo Gallery versions prior to 1.4.11 are vulnerable.
Coppermine Photo Gallery is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Coppermine Photo Gallery versions prior to 1.4.11 are vulnerable.
Exploit / POC
Coppermine Photo Gallery Albmgr.PHP SQL Injection Vulnerability
Attackers can exploit this issue via a web client.
The following exploit code is available:
Attackers can exploit this issue via a web client.
The following exploit code is available:
Solution / Fix
Coppermine Photo Gallery Albmgr.PHP SQL Injection Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Coppermine Photo Gallery Albmgr.PHP SQL Injection Vulnerability
References:
References:
- Coppermine Photo Gallery <= 1.4.10 (DarkFig)
- Coppermine Photo Gallery 1.4.11 Release Notes (Coppermine)
- Vendor Home Page (Coppermine)