CVE-2008-0506
medium · 6.8include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.
6.8
CVSS
58.9%
EPSS (exploit prob.)
99th
EPSS percentile
2008-01-31
Published
AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| coppermine | coppermine_photo_gallery | <= 1.4.14 |
Check a specific version with /api/v1/cve/match.
References
- http://coppermine-gallery.net/forum/index.php?topic=50103.0
- http://secunia.com/advisories/28682
- http://www.securityfocus.com/archive/1/487310/100/200/threaded
- http://www.securityfocus.com/bid/27512
- http://www.securitytracker.com/id?1019286
- http://www.vupen.com/english/advisories/2008/0367
- http://www.waraxe.us/advisory-65.html
- https://www.exploit-db.com/exploits/5019
- http://coppermine-gallery.net/forum/index.php?topic=50103.0
- http://secunia.com/advisories/28682
- http://www.securityfocus.com/archive/1/487310/100/200/threaded
- http://www.securityfocus.com/bid/27512
- http://www.securitytracker.com/id?1019286
- http://www.vupen.com/english/advisories/2008/0367
- http://www.waraxe.us/advisory-65.html
- https://www.exploit-db.com/exploits/5019
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2008-0506