peter bassill · operator
$ cve CVE-2007-0122 JSON

CVE-2007-0122 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 87)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS3.12% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2007-01-09
Last modified2026-06-16

Affected (1)

VendorProduct
copperminecoppermine photo gallery

Public exploits

SourceTitleDate
exploit-dbCoppermine Photo Gallery 1.4.11 - SQL Injection2007-01-05

References

→ the Explorer  ·  watch your stack  ·  NVD