Coppermine-gallery

Coppermine Photo Gallery

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 8.71%
  • Veröffentlicht 04.09.2012 20:55:01
  • Zuletzt bearbeitet 16.06.2026 23:39:51

Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter ...

Exploit
  • EPSS 1.34%
  • Veröffentlicht 23.09.2011 23:55:02
  • Zuletzt bearbeitet 16.06.2026 23:33:48

Coppermine Photo Gallery (CPG) 1.5.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by include/inspekt.php and certain other files...

  • EPSS 1.09%
  • Veröffentlicht 14.06.2011 17:55:06
  • Zuletzt bearbeitet 16.06.2026 23:31:24

Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-4667.

  • EPSS 1.05%
  • Veröffentlicht 14.06.2011 17:55:02
  • Zuletzt bearbeitet 16.06.2026 23:25:16

Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.4.27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Exploit
  • EPSS 1.81%
  • Veröffentlicht 11.01.2011 03:00:04
  • Zuletzt bearbeitet 16.06.2026 23:25:21

Multiple cross-site scripting (XSS) vulnerabilities in Coppermine Photo Gallery 1.5.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters to help.php, or (3) picfile_XXX parameter to searchnew...

Exploit
  • EPSS 1.34%
  • Veröffentlicht 09.09.2009 17:30:01
  • Zuletzt bearbeitet 16.06.2026 23:03:47

Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, which leaks the installation path in an error message.

Exploit
  • EPSS 1.34%
  • Veröffentlicht 09.09.2009 17:30:01
  • Zuletzt bearbeitet 16.06.2026 23:03:47

Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as the database table prefix via a direct request. NOTE: this might be leveraged for attacks against CVE-...

  • EPSS 6.3%
  • Veröffentlicht 06.08.2008 17:41:00
  • Zuletzt bearbeitet 16.06.2026 22:55:54

Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via ...

  • EPSS 2.11%
  • Veröffentlicht 05.08.2008 19:41:00
  • Zuletzt bearbeitet 16.06.2026 22:55:54

themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

  • EPSS 1.97%
  • Veröffentlicht 31.01.2008 20:00:00
  • Zuletzt bearbeitet 16.06.2026 22:49:45

Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_...