Coppermine
Coppermine Photo Gallery: vulnerabilidades y CVE
Coppermine Photo Gallery tiene 37 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE37
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-82482 | Baja (2) | 0.35% | — | 30 ago 2026 | A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation… |
| CVE-2026-3013 | Alta (8.7) | 0.67% | — | 11 mar 2026 | Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow to read content of… |
| CVE-2009-1616 | Media (4.3) | 1.7% | — | 11 may 2009 | Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via the css parameter, a different vector than… |
| CVE-2008-1840 | Media (6.5) | 1.8% | — | 16 abr 2008 | SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the… |
| CVE-2008-1841 | Media (6.8) | 1.9% | — | 16 abr 2008 | SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to execute arbitrary SQL commands via an input… |
| CVE-2008-0506 | Media (6.8) | 59% | — | 31 ene 2008 | include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell… |
| CVE-2008-0505 | Media (4.3) | 1.5% | — | 31 ene 2008 | Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters. |
| CVE-2007-5888 | Media (4.3) | 1.1% | — | 7 nov 2007 | Cross-site scripting (XSS) vulnerability in displayecard.php in Coppermine Photo Gallery (CPG) before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the data parameter. |
| CVE-2007-4976 | Media (6.5) | 8.5% | — | 19 sept 2007 | Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log… |
| CVE-2007-4977 | Baja (3.5) | 3.4% | — | 19 sept 2007 | Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the referer parameter. |
| CVE-2007-4283 | Alta (7.5) | 3.4% | — | 9 ago 2007 | PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the sourcedir parameter. |
| CVE-2007-3558 | Alta (7.5) | 1.0% | — | 4 jul 2007 | SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary SQL commands via an album password cookie to an unspecified component. |
| CVE-2007-1414 | Alta (10) | 5.2% | — | 12 mar 2007 | Multiple PHP remote file inclusion vulnerabilities in Coppermine Photo Gallery (CPG) allow remote attackers to execute arbitrary PHP code via a URL in the (1) cmd parameter to (a) image_processor.php or (b)… |
| CVE-2007-1107 | Alta (7.5) | 2.2% | — | 26 feb 2007 | SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie. NOTE: it was later reported that 1.4.10,… |
| CVE-2007-0835 | Media (6.5) | 1.5% | — | 8 feb 2007 | admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to execute arbitrary shell commands via shell metacharacters (";" semicolon) in the "Command line options for… |
| CVE-2007-0836 | Media (4) | 1.8% | — | 8 feb 2007 | admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote files via the (1) "Path to custom header include" and (2) "Path to… |
| CVE-2007-0122 | Media (6.5) | 3.1% | — | 9 ene 2007 | Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2)… |
| CVE-2007-0115 | Media (6) | 1.1% | — | 9 ene 2007 | Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error… |
| CVE-2006-6123 | Baja (2.6) | 1.3% | — | 26 nov 2006 | Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals enabled, allows remote attackers to bypass XSS protection and set arbitrary variables via a query string that causes the variable to be defined in… |
| CVE-2006-5622 | Alta (7.5) | 1.2% | — | 31 oct 2006 | SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary SQL commands via the aid parameter. |
| CVE-2006-4321 | Alta (7.5) | 3.2% | — | 24 ago 2006 | PHP remote file inclusion vulnerability in cpg.php in the Coppermine Photo Gallery component (com_cpg) 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the… |
| CVE-2006-3064 | Alta (7.5) | 1.3% | — | 19 jun 2006 | SQL injection vulnerability in the add_hit function in include/function.inc.php in Coppermine Photo Gallery (CPG) 1.4.8, when "Keep detailed hit statistics" is enabled, allows remote attackers to execute arbitrary SQL… |
| CVE-2006-2976 | Alta (7.5) | 1.4% | — | 12 jun 2006 | Unspecified vulnerability in usermgr.php in Coppermine Photo Gallery before 1.4.7 has unknown impact and remote attack vectors, possibly related to authorization/authentication errors. |
| CVE-2006-2514 | Alta (7.5) | 1.6% | — | 22 may 2006 | Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions. |
| CVE-2006-1909 | Media (5) | 3.6% | — | 20 abr 2006 | Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to… |
| CVE-2006-0873 | Media (5) | 1.7% | — | 24 feb 2006 | Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share… |
| CVE-2006-0872 | Media (5) | 2.4% | — | 24 feb 2006 | Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the lang… |
| CVE-2005-2676 | Media (4.3) | 1.2% | — | 23 ago 2005 | Cross-site scripting (XSS) vulnerability in displayimage.php in Coppermine Photo Gallery before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via EXIF data. |
| CVE-2005-1172 | Media (4.3) | 1.2% | — | 2 may 2005 | Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter. |
| CVE-2005-1225 | Alta (7.5) | 1.2% | — | 2 may 2005 | SQL injection vulnerability in Coppermine Photo Gallery 1.3.2 allows remote attackers to execute arbitrary SQL commands via the favs parameter to (1) init.inc.php or (2) zipdownload.php. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.