← All CVEs

CVE-2004-1987

high · 7.5

picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters.

7.5
CVSS
10.2%
EPSS (exploit prob.)
95th
EPSS percentile
2004-04-30
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
copperminecoppermine_photo_gallery1.0_rc3
copperminecoppermine_photo_gallery1.1_.0
copperminecoppermine_photo_gallery1.1_beta_2
copperminecoppermine_photo_gallery1.2
copperminecoppermine_photo_gallery1.2.1
copperminecoppermine_photo_gallery1.2.2_b
francisco_burziphp-nuke6.9
francisco_burziphp-nuke7.0
francisco_burziphp-nuke7.0_final
francisco_burziphp-nuke7.1
francisco_burziphp-nuke7.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-1987