CVE-2007-0835: Medium severity Coppermine Coppermine Photo Gallery vulnerability
admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to execute arbitrary shell commands via shell metacharacters (";" semicolon) in the "Command line options for ImageMagick" form field, when used as an option to ImageMagick's convert command. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0835?
CVE-2007-0835 has a medium severity rating due to its potential to allow remote command execution by authenticated users.
How do I fix CVE-2007-0835?
To fix CVE-2007-0835, upgrade your Coppermine Photo Gallery installation to version 1.4.11 or later.
What versions of Coppermine Photo Gallery are affected by CVE-2007-0835?
CVE-2007-0835 affects Coppermine Photo Gallery version 1.4.10 and possibly earlier versions.
What type of attack does CVE-2007-0835 facilitate?
CVE-2007-0835 facilitates remote command execution through shell metacharacters in an input field.
Who can exploit CVE-2007-0835?
CVE-2007-0835 can be exploited by remote authenticated users who have access to the admin options.