CVE-2004-1987: High severity Coppermine Coppermine Photo Gallery vulnerability
picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpegqual'] parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1987?
The severity of CVE-2004-1987 is classified as high due to the potential for remote command execution.
How do I fix CVE-2004-1987?
To fix CVE-2004-1987, it is recommended to upgrade to the latest version of Coppermine Photo Gallery or secure the affected parameters.
Which versions are affected by CVE-2004-1987?
CVE-2004-1987 affects Coppermine Photo Gallery versions 1.2.2b, 1.2.1, 1.1_beta_2, and prior, as well as specific PHP-Nuke versions.
Can CVE-2004-1987 be exploited without administrative privileges?
No, CVE-2004-1987 requires remote attackers to have administrative privileges to exploit the vulnerability.
What types of attacks can CVE-2004-1987 lead to?
CVE-2004-1987 can lead to arbitrary command execution, allowing attackers to execute commands on the server.