CVE-2004-1984

Current Description

Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message.

Basic Data

PublishedMay 02, 2004
Last ModifiedJuly 11, 2017
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeNVD-CWE-Other
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityLOW
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactPARTIAL
CVSS 2 - Availability ImpactNONE
CVSS 2 - Base Score5.0
SeverityMEDIUM
Exploitability Score10.0
Impact Score2.9
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationCoppermineCoppermine Photo Gallery1.0_rc3*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.1_.0*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.1_beta_2*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.2*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.2.1*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.2.2_b*******
    2.3ApplicationFrancisco BurziPhp-nuke6.9*******
    2.3ApplicationFrancisco BurziPhp-nuke7.0*******
    2.3ApplicationFrancisco BurziPhp-nuke7.0_final*******
    2.3ApplicationFrancisco BurziPhp-nuke7.1*******
    2.3ApplicationFrancisco BurziPhp-nuke7.2*******

Vulnerable Software List

VendorProductVersions
Coppermine Coppermine Photo Gallery 1.0_rc3, 1.1_.0, 1.1_beta_2, 1.2, 1.2.1, 1.2.2_b
Francisco Burzi Php-nuke 6.9, 7.0, 7.0_final, 7.1, 7.2

References

NameSourceURLTags
20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]http://marc.info/?l=bugtraq&m=108360247732014&w=2BUGTRAQ
11524http://secunia.com/advisories/11524SECUNIAExploit Vendor Advisory
1010001http://securitytracker.com/id?1010001SECTRACK
5756http://www.osvdb.org/5756OSVDB
6495http://www.osvdb.org/6495OSVDB
6496http://www.osvdb.org/6496OSVDB
6497http://www.osvdb.org/6497OSVDB
6498http://www.osvdb.org/6498OSVDB
6499http://www.osvdb.org/6499OSVDB
6500http://www.osvdb.org/6500OSVDB
http://www.waraxe.us/index.php?modname=sa&id=26http://www.waraxe.us/index.php?modname=sa&id=26MISCExploit Vendor Advisory
coppermine-multiple-path-disclosure(16039)https://exchange.xforce.ibmcloud.com/vulnerabilities/16039XF