CVE-2004-1988

Current Description

PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.

Basic Data

PublishedApril 30, 2004
Last ModifiedJuly 11, 2017
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeNVD-CWE-Other
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityLOW
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactPARTIAL
CVSS 2 - Availability ImpactPARTIAL
CVSS 2 - Base Score7.5
SeverityHIGH
Exploitability Score10.0
Impact Score6.4
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegetrue

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationCoppermineCoppermine Photo Gallery1.0_rc3*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.1_.0*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.1_beta_2*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.2*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.2.1*******
    2.3ApplicationCoppermineCoppermine Photo Gallery1.2.2_b*******
    2.3ApplicationFrancisco BurziPhp-nuke6.9*******
    2.3ApplicationFrancisco BurziPhp-nuke7.0*******
    2.3ApplicationFrancisco BurziPhp-nuke7.0_final*******
    2.3ApplicationFrancisco BurziPhp-nuke7.1*******
    2.3ApplicationFrancisco BurziPhp-nuke7.2*******

Vulnerable Software List

VendorProductVersions
Coppermine Coppermine Photo Gallery 1.0_rc3, 1.1_.0, 1.1_beta_2, 1.2, 1.2.1, 1.2.2_b
Francisco Burzi Php-nuke 6.9, 7.0, 7.0_final, 7.1, 7.2

References

NameSourceURLTags
20040502 [waraxe-2004-SA#026 - Multiple vulnerabilities in Coppermine Photo Gallery for PhpNuke]http://marc.info/?l=bugtraq&m=108360247732014&w=2BUGTRAQ
11524http://secunia.com/advisories/11524SECUNIAExploit Vendor Advisory
1010001http://securitytracker.com/id?1010001SECTRACK
5761http://www.osvdb.org/5761OSVDB
10253http://www.securityfocus.com/bid/10253BIDExploit Vendor Advisory
http://www.waraxe.us/index.php?modname=sa&id=26http://www.waraxe.us/index.php?modname=sa&id=26MISCExploit Vendor Advisory
coppermine-multiple-file-include(16041)https://exchange.xforce.ibmcloud.com/vulnerabilities/16041XF