This application requires Javascript for optimal performance.

Coppermine.Photo.Gallery.ThumbNails.PHP.SQL.Injection

Release Date

Mar 18, 2010

Severity

medium

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Description

This indicates an attack attempt to exploit a SQL injection vulnerability in
Coppermine Photo Gallery.

The vulnerability is a result of the application's failure to properly sanitize user input before using it in a SQL query. As a result, a remote attacker can send a crafted query to execute SQL commands on a vulnerable server.

Affected Products

Coppermine Photo Gallery 1.3.1

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-1107

Reference/s

http://www.securityfocus.com/bid/22709 (BugTraq)

Reference: VID-18261