CVE-2008-7186
Last modified
CVE-2008-7186 is a vulnerability of currently unknown severity. Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as the database table prefix via a direct request. NOTE: this might be leveraged for attacks against CVE-2008-0504.. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as the database table prefix via a direct request. NOTE: this might be leveraged for attacks against CVE-2008-0504.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Coppermine-Gallery | Coppermine Photo Gallery | 1.4.14 |
References
- http://www.vupen.com/english/advisories/2008/0367Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0367Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-7186?
How severe is CVE-2008-7186?
How do I fix CVE-2008-7186?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-7180del_query1.php in Telephone Directory 2008 allows remote att…
- CVE-2008-7181Butterfly Organizer 2.0.0 allows remote attackers to (1) del…
- CVE-2008-7182Buffer overflow in the IMAP service in NetWin Surgemail 3.9e…
- CVE-2008-7183PHP remote file inclusion vulnerability in eva/index.php in …
- CVE-2008-7184Cross-site scripting (XSS) vulnerability in Diigo Toolbar an…
- CVE-2008-7185GNOME Rhythmbox 0.11.5 allows remote attackers to cause a de…
- CVE-2008-7187Coppermine Photo Gallery (CPG) 1.4.14 allows remote attacker…
- CVE-2008-7188ClipShare 2.6 does not properly restrict access to certain f…
- CVE-2008-7189Multiple unspecified vulnerabilities in Local Media Browser …
- CVE-2008-7190Unspecified vulnerability in Adium before 1.2 has unknown im…
- CVE-2008-7191Unspecified vulnerability in Polipo before 1.0.4 allows remo…
- CVE-2008-7192Cross-site request forgery (CSRF) vulnerability in index.php…
Are you affected by CVE-2008-7186?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
