CVE-2007-0115
Estado: ModificadaMedia (6)—
Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P
- Puntuación base: 6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.14%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://acid-root.new.fr/poc/19070104.txt
- http://osvdb.org/33383
- http://securityreason.com/securityalert/2107
- http://www.attrition.org/pipermail/vim/2007-January/001218.html
- http://www.securityfocus.com/archive/1/456051/100/0/threaded
- http://acid-root.new.fr/poc/19070104.txt
- http://osvdb.org/33383
- http://securityreason.com/securityalert/2107
- http://www.attrition.org/pipermail/vim/2007-January/001218.html
- http://www.securityfocus.com/archive/1/456051/100/0/threaded
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-0115",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-01-09T02:28:00.000",
"references": [
{
"url": "http://acid-root.new.fr/poc/19070104.txt",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/33383",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/2107",
"source": "cve@mitre.org"
},
{
"url": "http://www.attrition.org/pipermail/vim/2007-January/001218.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/456051/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://acid-root.new.fr/poc/19070104.txt",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/33383",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/2107",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.attrition.org/pipermail/vim/2007-January/001218.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/456051/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php."
},
{
"lang": "es",
"value": "Vulnerabilidad de inyección de código estático en coppermine Photo Gallery 1.4.10 y anteriores permite a administradores autenticados remotamente ejecutar código PHP de su elección a través del Nombre de Usuario para login.php, el cual es inyectado dentro de un mensaje de error en security.log.php, que puede ser accedido utilizando viewlog.php."
}
],
"lastModified": "2026-06-16T22:34:56.717",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:coppermine:coppermine_photo_gallery:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7E1F67DD-8ED5-4E97-9EBE-3EDC01DE60BB",
"versionEndIncluding": "1.4.10"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}