VDB
CVE-2008-1840
CVE-2008-1840
PUBLISHED
CVSS 6.5 MEDIUM
SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is used for an upload.
EPSS 0.52% · 67.0th percentile
Risk Scores
CVSS 2.0
6.5
EPSS Score
0.52%
67.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| coppermine | coppermine_photo_gallery | 1.4.1, 1.4.2, 1.4.3 |
Timeline
- Apr 16, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- coppermine-upload-sql-injection(41784) vdb
- http://sourceforge.net/project/shownotes.php?group_id=89658&release_id=592069 url
- 28766 vdb
- 29795 third-party-advisory
- 44345 vdb
- http://forum.coppermine-gallery.net/index.php/topic%2C51787%2C0.html url
- https://nvd.nist.gov/vuln/detail/CVE-2008-1840 advisory
- http://forum.coppermine-gallery.net/index.php/topic,51787,0.html url