Coppermine.Photo.Gallery.Remote.Command

NameCoppermine.Photo.Gallery.Remote.Command.Execution
Last Updated DateMar 09, 2010
Release DateFeb 04, 2008
SeverityHigh
ImpactSystem compromise: remote code execution.
DescriptionThis indicates an attempt to exploit one of several remote command execution vulnerabilities in Coppermine Photo Gallery.

The vulnerabilities are caused by an error that occurs when the vulnerable software handles a malformed request. It allows a remote attacker to execute arbitrary code by sending a crafted request.
Affected ProductsCoppermine Photo Gallery version 1.4.4 and prior.
Recommended ActionsApply the patch available from the web site:
http://downloads.sourceforge.net/coppermine/cpg1.4.15.zip
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0506
Reference/shttp://www.securityfocus.com/bid/27512 (BugTraq)
http://www.vupen.com/english/advisories/2008/0367 (FrSIRT)
Reference: VID-15375