CVE-2008-3481: Code Injection
Published Aug 5, 2008
·Updated
themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
Affected Software
31 affected components
Coppermine-gallery Coppermine Photo Gallery=1.4.17
Coppermine-gallery Coppermine Photo Gallery=1.4.11
Coppermine-gallery Coppermine Photo Gallery=1.4.14
Coppermine-gallery Coppermine Photo Gallery=1.2.0-rc2
Coppermine-gallery Coppermine Photo Gallery=1.4.8
Coppermine-gallery Coppermine Photo Gallery=1.2.1
Coppermine-gallery Coppermine Photo Gallery=1.4.7
Coppermine-gallery Coppermine Photo Gallery=1.4.0-alpha
Coppermine-gallery Coppermine Photo Gallery=1.4.2
Coppermine-gallery Coppermine Photo Gallery=1.4.16
Coppermine-gallery Coppermine Photo Gallery=1.4.3
Coppermine-gallery Coppermine Photo Gallery=1.2.1-b
Coppermine-gallery Coppermine Photo Gallery=1.4.15
Coppermine-gallery Coppermine Photo Gallery=1.0-rc3
Coppermine-gallery Coppermine Photo Gallery=1.4.5
Coppermine-gallery Coppermine Photo Gallery=1.1
Coppermine-gallery Coppermine Photo Gallery=1.2.0
Coppermine-gallery Coppermine Photo Gallery=1.4.4
Coppermine-gallery Coppermine Photo Gallery=1.2.1-b-nuke
Coppermine-gallery Coppermine Photo Gallery=1.4.9
Coppermine-gallery Coppermine Photo Gallery<=1.4.18
Coppermine-gallery Coppermine Photo Gallery=1.4.12
Coppermine-gallery Coppermine Photo Gallery=1.4.13
Coppermine-gallery Coppermine Photo Gallery=1.4.10
Coppermine-gallery Coppermine Photo Gallery=1.4.6
Coppermine-gallery Coppermine Photo Gallery=1.3.0
Coppermine-gallery Coppermine Photo Gallery=1.1.0
Coppermine-gallery Coppermine Photo Gallery=1.4.1-beta
Coppermine-gallery Coppermine Photo Gallery=1.0
Coppermine-gallery Coppermine Photo Gallery=1.4-beta
Coppermine-gallery Coppermine Photo Gallery=1.1-beta_2
Event History
Aug 5, 2008
CVE Published
via MITRE·07:20 PM
Data Sourced
via MITRE·07:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-3481?
CVE-2008-3481 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2008-3481?
To fix CVE-2008-3481, upgrade to Coppermine Photo Gallery version 1.4.19 or later.
3
What versions are affected by CVE-2008-3481?
CVE-2008-3481 affects Coppermine Photo Gallery versions 1.4.18 and earlier.
4
What kind of information is exposed by CVE-2008-3481?
CVE-2008-3481 could expose the installation path of the Coppermine Photo Gallery through error messages.
5
Is CVE-2008-3481 exploitable remotely?
Yes, CVE-2008-3481 can be exploited remotely by attackers to obtain sensitive information.