CVE-2008-1840: SQL Injection
SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is used for an upload.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1840?
CVE-2008-1840 has a medium severity rating due to its potential for SQL injection.
How do I fix CVE-2008-1840?
To fix CVE-2008-1840, upgrade to Coppermine Photo Gallery version 1.4.17 or later.
Who is affected by CVE-2008-1840?
Remote authenticated users and user-assisted remote HTTP servers are affected by CVE-2008-1840.
What does CVE-2008-1840 exploit?
CVE-2008-1840 exploits SQL injection vulnerabilities in the upload.php file of affected versions of Coppermine Photo Gallery.
What versions of Coppermine Photo Gallery are vulnerable to CVE-2008-1840?
Coppermine Photo Gallery versions 1.4.16 and earlier are vulnerable to CVE-2008-1840.