CVE-2007-0122

N/A Unknown
Published: January 09, 2007 Modified: April 23, 2026
View on NVD

Description

Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/35852
Source: cve@mitre.org
http://osvdb.org/35853
Source: cve@mitre.org
http://osvdb.org/35854
Source: cve@mitre.org
http://osvdb.org/35855
Source: cve@mitre.org
http://osvdb.org/35856
Source: cve@mitre.org
http://www.securityfocus.com/bid/21894
Source: cve@mitre.org
Exploit
http://acid-root.new.fr/poc/19070104.txt
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/35852
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/35853
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/35854
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/35855
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/35856
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25846
Source: af854a3a-2127-422b-91ae-364da2661108
http://securityreason.com/securityalert/2123
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/456051/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/21894
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
https://www.exploit-db.com/exploits/3085
Source: af854a3a-2127-422b-91ae-364da2661108

22 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.4%
85th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

coppermine