CVE Vulnerabilities

CVE-2004-1987

Published: Apr 30, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG[impath] or (2) $CONFIG[jpeg_qual] parameters.

Affected Software

NameVendorStart VersionEnd Version
Coppermine_photo_galleryCoppermine1.0_rc3 (including)1.0_rc3 (including)
Coppermine_photo_galleryCoppermine1.1_.0 (including)1.1_.0 (including)
Coppermine_photo_galleryCoppermine1.1_beta_2 (including)1.1_beta_2 (including)
Coppermine_photo_galleryCoppermine1.2 (including)1.2 (including)
Coppermine_photo_galleryCoppermine1.2.1 (including)1.2.1 (including)
Coppermine_photo_galleryCoppermine1.2.2_b (including)1.2.2_b (including)
Php-nukeFrancisco_burzi6.9 (including)6.9 (including)
Php-nukeFrancisco_burzi7.0 (including)7.0 (including)
Php-nukeFrancisco_burzi7.0_final (including)7.0_final (including)
Php-nukeFrancisco_burzi7.1 (including)7.1 (including)
Php-nukeFrancisco_burzi7.2 (including)7.2 (including)

References