CVE-2007-0122 EXPLOIT
6.5
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 87)
Patch early
A public exploit exists.
Description
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.
Scoring
| CVSS | 6.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| EPSS | 3.12% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-01-09 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| coppermine | coppermine photo gallery |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Coppermine Photo Gallery 1.4.11 - SQL Injection | 2007-01-05 |
References
- http://acid-root.new.fr/poc/19070104.txt
- http://osvdb.org/35852
- http://osvdb.org/35853
- http://osvdb.org/35854
- http://osvdb.org/35855
- http://osvdb.org/35856
- http://secunia.com/advisories/25846
- http://securityreason.com/securityalert/2123
- http://www.securityfocus.com/archive/1/456051/100/0/threaded
- http://www.securityfocus.com/bid/21894
- https://www.exploit-db.com/exploits/3085
- http://acid-root.new.fr/poc/19070104.txt
- http://osvdb.org/35852
- http://osvdb.org/35853
- http://osvdb.org/35854
- http://osvdb.org/35855
- http://osvdb.org/35856
- http://secunia.com/advisories/25846
- http://securityreason.com/securityalert/2123
- http://www.securityfocus.com/archive/1/456051/100/0/threaded
→ the Explorer · watch your stack · NVD