VDB
CVE-2008-0506
CVE-2008-0506
PUBLISHED
CVSS 6.800000190734863 MEDIUM
include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.
EPSS 88.38% · 99.5th percentile
Risk Scores
CVSS 2.0
6.800000190734863
EPSS Score
88.38%
99.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| coppermine | coppermine_photo_gallery | 0 |
Timeline
- Jan 31, 2008 CVE Published
- Jul 3, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
References
- http://www.waraxe.us/advisory-65.html url
- http://coppermine-gallery.net/forum/index.php?topic=50103.0 url
- ADV-2008-0367 vdb
- 27512 vdb
- 28682 third-party-advisory
- 20080130 [waraxe-2008-SA#065] - Remote Shell Command Execution in Coppermine 1.4.14 mailing-list
- 1019286 vdb
- 5019 exploit
- https://nvd.nist.gov/vuln/detail/CVE-2008-0506 advisory