VDB
CVE-2007-0122
CVE-2007-0122
PUBLISHED
CVSS 6.5 MEDIUM
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.
EPSS 2.44% · 85.5th percentile
Risk Scores
CVSS 2.0
6.5
EPSS Score
2.44%
85.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| coppermine | coppermine_photo_gallery | *, 1.0, 1.0_rc3 |
| n/a | n/a | * |
Timeline
- Jan 9, 2007 CVE Published
- Jul 30, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 35853 vdb
- 2123 third-party-advisory
- 25846 third-party-advisory
- http://acid-root.new.fr/poc/19070104.txt url
- 3085 exploit
- 35854 vdb
- 35852 vdb
- 20070105 Coppermine Photo Gallery <= 1.4.10 SQL Injection Exploit mailing-list
- 21894 vdb
- 35856 vdb
- 35855 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2007-0122 advisory