Coppermine Photo Gallery Multiple Input Validation Vulnerabilities
BID:25698
Info
Coppermine Photo Gallery Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 25698 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-4976 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | L4teral is credited with discovering these vulnerabilities. |
| Vulnerable: |
Coppermine Photo Gallery 1.4.12 Coppermine Photo Gallery 1.4.11 Coppermine Photo Gallery 1.4.10 Coppermine Photo Gallery 1.4.9 Coppermine Photo Gallery 1.4.4 Coppermine Photo Gallery 1.4.2 Coppermine Photo Gallery 1.4 |
| Not Vulnerable: |
Coppermine Photo Gallery 1.4.13 |
Discussion
Coppermine Photo Gallery Multiple Input Validation Vulnerabilities
Coppermine Photo Gallery is prone to a cross-site scripting issue and a local file-include issue.
Attackers can exploit these issues to steal cookie-based authentication credentials, execute arbitrary code, and retrieve arbitrary content within the context of the webserver process.
Coppermine Photo Gallery 1.4.12 is vulnerable; other versions may also be affected.
Coppermine Photo Gallery is prone to a cross-site scripting issue and a local file-include issue.
Attackers can exploit these issues to steal cookie-based authentication credentials, execute arbitrary code, and retrieve arbitrary content within the context of the webserver process.
Coppermine Photo Gallery 1.4.12 is vulnerable; other versions may also be affected.
Exploit / POC
Coppermine Photo Gallery Multiple Input Validation Vulnerabilities
To exploit the cross-site scripting issue, an attacker must entice an unsuspecting victim into following a malicious URI. An attacker can exploit the local file-include issue through a browser.
The following proof-of-concept URIs are available:
http://www.example.com/cpg/mode.php?admin_mode=1&referer=javascript:alert(document.cookie)
http://localhost/cpg/viewlog.php?log=../../../../../../../../../etc/passwd%00
To exploit the cross-site scripting issue, an attacker must entice an unsuspecting victim into following a malicious URI. An attacker can exploit the local file-include issue through a browser.
The following proof-of-concept URIs are available:
http://www.example.com/cpg/mode.php?admin_mode=1&referer=javascript:alert(document.cookie)
http://localhost/cpg/viewlog.php?log=../../../../../../../../../etc/passwd%00
Solution / Fix
Coppermine Photo Gallery Multiple Input Validation Vulnerabilities
Solution:
The vendor released an update to address these issues. Please see the references for more information.
Coppermine Photo Gallery 1.4
Coppermine Photo Gallery 1.4.10
Coppermine Photo Gallery 1.4.11
Coppermine Photo Gallery 1.4.12
Coppermine Photo Gallery 1.4.2
Coppermine Photo Gallery 1.4.4
Coppermine Photo Gallery 1.4.9
Solution:
The vendor released an update to address these issues. Please see the references for more information.
Coppermine Photo Gallery 1.4
-
Coppermine cpg1.4.13.zip
http://downloads.sourceforge.net/coppermine/cpg1.4.13.zip?modtime=1189 793460&big_mirror=0
Coppermine Photo Gallery 1.4.10
-
Coppermine cpg1.4.13.zip
http://downloads.sourceforge.net/coppermine/cpg1.4.13.zip?modtime=1189 793460&big_mirror=0
Coppermine Photo Gallery 1.4.11
-
Coppermine cpg1.4.13.zip
http://downloads.sourceforge.net/coppermine/cpg1.4.13.zip?modtime=1189 793460&big_mirror=0
Coppermine Photo Gallery 1.4.12
-
Coppermine cpg1.4.13.zip
http://downloads.sourceforge.net/coppermine/cpg1.4.13.zip?modtime=1189 793460&big_mirror=0
Coppermine Photo Gallery 1.4.2
-
Coppermine cpg1.4.13.zip
http://downloads.sourceforge.net/coppermine/cpg1.4.13.zip?modtime=1189 793460&big_mirror=0
Coppermine Photo Gallery 1.4.4
-
Coppermine cpg1.4.13.zip
http://downloads.sourceforge.net/coppermine/cpg1.4.13.zip?modtime=1189 793460&big_mirror=0
Coppermine Photo Gallery 1.4.9
-
Coppermine cpg1.4.13.zip
http://downloads.sourceforge.net/coppermine/cpg1.4.13.zip?modtime=1189 793460&big_mirror=0
References
Coppermine Photo Gallery Multiple Input Validation Vulnerabilities
References:
References:
- Coppermine Photo Gallery Homepage (Coppermine Photo Gallery)
- Coppermine <= 1.4.12 Cross Site Scripting and Local File Inclusion ([email protected])
- Coppermine 1.4.13 - Security release. (Coppermine)