CVE-2007-4283: High severity Coppermine Coppermine Photo Gallery vulnerability
Published Aug 9, 2007
·Updated
PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the sourcedir parameter.
Affected Software
1 affected component
Coppermine Coppermine Photo Gallery=1.3.1
Event History
Aug 9, 2007
CVE Published
09:17 PM
Aug 10, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4283?
CVE-2007-4283 has a medium severity level due to its potential for remote code execution.
2
How do I fix CVE-2007-4283?
To fix CVE-2007-4283, upgrade to a newer version of Coppermine Photo Gallery that does not contain this vulnerability.
3
What types of attacks can be executed through CVE-2007-4283?
CVE-2007-4283 allows attackers to execute arbitrary PHP code on the affected server.
4
Which software version is vulnerable to CVE-2007-4283?
CVE-2007-4283 specifically affects Coppermine Photo Gallery version 1.3.1.
5
How can I mitigate the risks associated with CVE-2007-4283?
To mitigate risks from CVE-2007-4283, implement input validation and avoid using remote file inclusions in your application.