FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-0506

This CVE name corresponds to:

Entered Topic
2008-02-25 coppermine -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-0506
Phase Assigned(20080131)

Description

include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.

References

Source Reference
BUGTRAQ 20080130 [waraxe-2008-SA#065] - Remote Shell Command Execution in Coppermine 1.4.14
MILW0RM 5019
MISC http://www.waraxe.us/advisory-65.html
CONFIRM http://coppermine-gallery.net/forum/index.php?topic=50103.0
BID 27512
SECTRACK 1019286
SECUNIA 28682
VUPEN ADV-2008-0367