CVE-2007-4977: XSS
Published Sep 19, 2007
·Updated
Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the referer parameter.
Affected Software
7 affected components
Coppermine Coppermine Photo Gallery=1.4
Coppermine Coppermine Photo Gallery=1.4.2
Coppermine Coppermine Photo Gallery=1.4.4
Coppermine Coppermine Photo Gallery=1.4.9
Coppermine Coppermine Photo Gallery=1.4.10
Coppermine Coppermine Photo Gallery=1.4.11
Coppermine Coppermine Photo Gallery=1.4.12
Remediation
Patch Available
Patch Available
Patch Available
Event History
Sep 19, 2007
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4977?
CVE-2007-4977 has a medium severity rating due to its potential impact on user data through cross-site scripting.
2
How do I fix CVE-2007-4977?
To fix CVE-2007-4977, upgrade Coppermine Photo Gallery to version 1.4.13 or later, which addresses this vulnerability.
3
What versions of Coppermine are affected by CVE-2007-4977?
CVE-2007-4977 affects Coppermine Photo Gallery versions 1.4.11 and earlier, including all 1.4.x versions.
4
What type of vulnerability is CVE-2007-4977?
CVE-2007-4977 is classified as a cross-site scripting (XSS) vulnerability.
5
Can CVE-2007-4977 lead to data theft?
Yes, CVE-2007-4977 can potentially allow attackers to steal user session cookies and other sensitive information through XSS.