VYPR

CPG

by Coppermine

CVEs (9)

  • CVE-2018-14478MedMay 7, 2019
    risk 0.40cvss 6.1epss 0.01

    ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.

  • CVE-2007-4976Sep 19, 2007
    risk 0.04cvss epss 0.09

    Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log parameter.

  • CVE-2008-3481Aug 5, 2008
    risk 0.03cvss epss 0.02

    themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

  • CVE-2008-0504Jan 31, 2008
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to…

  • CVE-2008-7187Sep 9, 2009
    risk 0.00cvss epss 0.01

    Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, which leaks the installation path in an error message.

  • CVE-2008-1840Apr 16, 2008
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is…

  • CVE-2008-1841Apr 16, 2008
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to execute arbitrary SQL commands via an input field associated with the session_id variable, as exploited…

  • CVE-2008-0505Jan 31, 2008
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters.

  • CVE-2007-5888Nov 7, 2007
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in displayecard.php in Coppermine Photo Gallery (CPG) before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the data parameter.