CVE-2008-0504: SQL Injection
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cidarray parameter to reviewcom.php.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0504?
CVE-2008-0504 has been classified as a medium to high severity vulnerability due to its potential for remote SQL command execution.
How do I fix CVE-2008-0504?
To fix CVE-2008-0504, upgrade your Coppermine Photo Gallery to version 1.4.15 or later.
What versions of Coppermine Photo Gallery are affected by CVE-2008-0504?
CVE-2008-0504 affects all versions of Coppermine Photo Gallery before 1.4.15, including 1.2.x and 1.4.x series.
What types of SQL injection vulnerabilities are present in CVE-2008-0504?
CVE-2008-0504 has multiple SQL injection vulnerabilities that allow remote authenticated administrators to execute arbitrary SQL commands via specific parameters.
What are the specific parameters affected by CVE-2008-0504?
The specific parameters affected by CVE-2008-0504 include albumid, startpic, numpics in util.php, and cid_array in reviewcom.php.