漏洞信息详情
Coppermine Photo Gallery 'thumbnails.php' SQL注入漏洞
- CNNVD编号:CNNVD-200702-519
- 危害等级: 高危
- CVE编号: CVE-2007-1107
- 漏洞类型: SQL注入
- 发布时间: 2007-02-26
- 威胁类型: 远程
- 更新时间: 2009-09-15
- 厂 商: coppermine
- 漏洞来源: s0cratex
漏洞简介
Coppermine Photo Gallery (CPG) 1.3.x版本的thumbnails.php中存在SQL注入漏洞。远程认证用户可借助cpg131_fav cookie执行任意SQL命令。
漏洞公告
参考网址
来源: XF
名称: copperminephoto-thumbnails-sql-injection(39806)
链接:http://xforce.iss.net/xforce/xfdb/39806
来源: BID
名称: 27372
链接:http://www.securityfocus.com/bid/27372
来源: BUGTRAQ
名称: 20070224 Coppermine Photo Gallery 1.3.x Blind SQL Injection Exploit
链接:http://www.securityfocus.com/archive/1/archive/1/461158/100/0/threaded
来源: MILW0RM
名称: 4961
链接:http://www.milw0rm.com/exploits/4961
来源: MILW0RM
名称: 4950
链接:http://www.milw0rm.com/exploits/4950
来源: MILW0RM
名称: 3371
链接:http://www.milw0rm.com/exploits/3371
来源: OSVDB
名称: 33133
链接:http://osvdb.org/33133
来源: XF
名称: coppermine-thumbnails-sql-injection(32688)
链接:http://xforce.iss.net/xforce/xfdb/32688
来源: BID
名称: 22709
链接:http://www.securityfocus.com/bid/22709
来源: SREASON
名称: 2297
链接:http://securityreason.com/securityalert/2297
受影响实体
- Coppermine Coppermine_photo_gallery:1.3
- Coppermine Coppermine_photo_gallery:1.3.2
- Coppermine Coppermine_photo_gallery:1.3.3
- Coppermine Coppermine_photo_gallery:1.3.4
补丁
暂无
评论