First published: Mon Mar 12 2007(Updated: )
Multiple PHP remote file inclusion vulnerabilities in Coppermine Photo Gallery (CPG) allow remote attackers to execute arbitrary PHP code via a URL in the (1) cmd parameter to (a) image_processor.php or (b) picmgmt.inc.php, or the (2) path parameter to (c) include/functions.php, (d) include/plugin_api.inc.php, (e) index.php, or (f) pluginmgr.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Coppermine Coppermine Photo Gallery |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1414 has a CVSS score indicating it is a high-severity vulnerability that allows remote code execution.
To fix CVE-2007-1414, update to the latest version of Coppermine Photo Gallery that addresses these vulnerabilities.
CVE-2007-1414 includes multiple PHP remote file inclusion vulnerabilities affecting certain parameters in Coppermine Photo Gallery.
CVE-2007-1414 affects users running specific versions of Coppermine Photo Gallery that have not been patched against PHP remote file inclusion.
Attackers exploiting CVE-2007-1414 can execute arbitrary PHP code on the affected server by using crafted URL parameters.