CVE-2007-1107: SQL Injection
SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131fav cookie. NOTE: it was later reported that 1.4.10, 1.4.14, and other 1.4.x versions are also affected using similar cookies.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1107?
CVE-2007-1107 is classified as a high severity vulnerability affecting multiple versions of Coppermine Photo Gallery.
How do I fix CVE-2007-1107?
To fix CVE-2007-1107, it is recommended to upgrade to the latest version of Coppermine Photo Gallery that addresses the SQL injection issue.
What versions are affected by CVE-2007-1107?
CVE-2007-1107 affects Coppermine Photo Gallery versions 1.3.x and certain 1.4.x versions using vulnerable cookie handling.
Can unauthorized users exploit CVE-2007-1107?
No, CVE-2007-1107 requires remote authenticated users to exploit the SQL injection vulnerability.
What type of vulnerability is CVE-2007-1107?
CVE-2007-1107 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.