CVE-2006-6123
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/11/2006
Last modified:
09/04/2025
Description
Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals enabled, allows remote attackers to bypass XSS protection and set arbitrary variables via a query string that causes the variable to be defined in global space, with separate _GET, _REQUEST, or other critical parameters, which are unset by the protection scheme and prevent the original variable from being detected.
Impact
Base Score 2.0
2.60
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:coppermine:coppermine_photo_gallery:1.4.8_stable:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/bugtraq/2006-06/0482.html
- http://myimei.com/security/2006-06-20/coppermine-148parameter-cleanup-system-bypassregistering-global-varables.html
- http://secunia.com/advisories/20597
- http://securityreason.com/securityalert/1914
- http://svn.sourceforge.net/viewvc/coppermine?view=rev&revision=3133
- http://www.osvdb.org/27618
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27376
- http://archives.neohapsis.com/archives/bugtraq/2006-06/0482.html
- http://myimei.com/security/2006-06-20/coppermine-148parameter-cleanup-system-bypassregistering-global-varables.html
- http://secunia.com/advisories/20597
- http://securityreason.com/securityalert/1914
- http://svn.sourceforge.net/viewvc/coppermine?view=rev&revision=3133
- http://www.osvdb.org/27618
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27376