CVE-2008-7186: Medium severity coppermine gallery vulnerability
Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as the database table prefix via a direct request. NOTE: this might be leveraged for attacks against CVE-2008-0504.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7186?
CVE-2008-7186 is considered a medium severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2008-7186?
To mitigate CVE-2008-7186, restrict access to update.php by implementing access control measures.
What software is affected by CVE-2008-7186?
CVE-2008-7186 specifically affects Coppermine Photo Gallery version 1.4.14.
What type of information can be leaked due to CVE-2008-7186?
CVE-2008-7186 allows attackers to obtain sensitive information such as the database table prefix.
What is the impact of CVE-2008-7186 on system security?
CVE-2008-7186 can lead to further attacks, especially in conjunction with other vulnerabilities like CVE-2008-0504.