CVE-2006-6123
Last modified
CVE-2006-6123 is a vulnerability of currently unknown severity. Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals enabled, allows remote attackers to bypass XSS protection and set arbitrary variables via a query string that causes the variable to be defined in global space, with separate _GET, _REQUEST, or other critical parameters, which are unset by the protection scheme and prevent the original variable from being detected.. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals enabled, allows remote attackers to bypass XSS protection and set arbitrary variables via a query string that causes the variable to be defined in global space, with separate _GET, _REQUEST, or other critical parameters, which are unset by the protection scheme and prevent the original variable from being detected.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Coppermine | Coppermine Photo Gallery | 1.4.8_stable |
References
- http://secunia.com/advisories/20597Vendor Advisory
- http://secunia.com/advisories/20597Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-6123?
How severe is CVE-2006-6123?
How do I fix CVE-2006-6123?
Are you affected by CVE-2006-6123?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
