NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6917 | CVE-2008-7186 | Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as the database table prefix via a direct request. NOTE: this might be leveraged for attacks against CVE-2008-0504. | 2 | 5 | Medium | 2017-01-03 | 2009-09-10 | View | |
| 64684 | CVE-2006-6123 | Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals enabled, allows remote attackers to bypass XSS protection and set arbitrary variables via a query string that causes the variable to be defined in global space, with separate _GET, _REQUEST, or other critical parameters, which are unset by the protection scheme and prevent the original variable from being detected. | 2 | 2.6 | Low | 2016-12-20 | 2008-09-05 | View | |
| 10294 | CVE-2011-3722 | Coppermine Photo Gallery (CPG) 1.5.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by include/inspekt.php and certain other files. | 2 | 5 | Medium | 2017-01-07 | 2012-03-13 | View | |
| 72361 | CVE-2004-1984 | Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 66972 | CVE-2005-1226 | Coppermine Photo Gallery 1.3.2 stores passwords in plaintext, which allows remote attackers to obtain sensitive information. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 2663 of 17672, showing 5 records out of 88360 total, starting on record 13311, ending on 13315