Description: A vulnerability has been reported in Coppermine
Photo Gallery, which can be exploited by malicious people to conduct
SQL injection attacks.
Input passed to unspecified cookies in bridge/coppermine.inc.php is not
properly sanitised before being used in SQL queries. This can be
exploited to manipulate SQL queries by injecting arbitrary SQL code.
The vulnerability is reported in version 1.4.17. Prior versions may also be affected.
Solution: Update to version 1.4.18.
Provided and/or discovered by: Reported by the vendor.
Original Advisory: http://forum.coppermine-gallery.net/index.php/topic,51882.0.html
|