First published: Thu Jan 31 2008(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Coppermine Coppermine Photo Gallery | <=1.4.14 | |
Coppermine Coppermine Photo Gallery | =1.4.11 | |
Coppermine Coppermine Photo Gallery | =1.4.12 | |
Coppermine Coppermine Photo Gallery | =1.4.13 | |
Coppermine Coppermine Photo Gallery | =1.4.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0505 has a medium severity rating due to the potential for remote code execution via cross-site scripting (XSS).
To fix CVE-2008-0505, you should upgrade to Coppermine Photo Gallery version 1.4.15 or later.
CVE-2008-0505 affects all versions of Coppermine Photo Gallery prior to 1.4.15, including versions 1.4.10 to 1.4.14.
Attackers can exploit CVE-2008-0505 to inject arbitrary web scripts or HTML, potentially compromising the integrity of the affected site.
Yes, CVE-2008-0505 is a known vulnerability that has been documented and discussed within the cybersecurity community.