CVE-2004-1985

Current Description

Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.

Basic Data

PublishedApril 30, 2004
Last ModifiedJuly 11, 2017
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeNVD-CWE-Other
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:M/Au:N/C:N/I:P/A:N
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityMEDIUM
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactNONE
CVSS 2 - Availability ImpactNONE
CVSS 2 - Base Score4.3
SeverityMEDIUM
Exploitability Score8.6
Impact Score2.9
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationCoppermineCoppermine Photo Gallery1.0_rc3*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.1_.0*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.1_beta_2*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.2*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.2.1*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.2.2_b*******
    2.3ApplicationFrancisco BurziPhp-nuke6.9*******
    2.3ApplicationFrancisco BurziPhp-nuke7.0*******
    2.3ApplicationFrancisco BurziPhp-nuke7.0_final*******
    2.3ApplicationFrancisco BurziPhp-nuke7.1*******
    2.3ApplicationFrancisco BurziPhp-nuke7.2*******

Vulnerable Software List

VendorProductVersions
Coppermine Coppermine Photo Gallery 1.0_rc3, 1.1_.0, 1.1_beta_2, 1.2, 1.2.1, 1.2.2_b
Francisco Burzi Php-nuke 6.9, 7.0, 7.0_final, 7.1, 7.2

References

NameSourceURLTags
20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]http://marc.info/?l=bugtraq&m=108360247732014&w=2BUGTRAQ
11524http://secunia.com/advisories/11524SECUNIAVendor Advisory
5757http://www.osvdb.org/5757OSVDB
10253http://www.securityfocus.com/bid/10253BIDExploit Vendor Advisory
http://www.waraxe.us/index.php?modname=sa&id=26http://www.waraxe.us/index.php?modname=sa&id=26MISC
coppermine-menuincpho-xss(16040)https://exchange.xforce.ibmcloud.com/vulnerabilities/16040XF