← Back

CVE-2006-6123

nvd nist
Published: Nov 26, 2006Modified: Apr 23, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:N/I:P/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

Coppermine Photo Gallery (CPG) 1.4.8 stable, with register_globals enabled, allows remote attackers to bypass XSS protection and set arbitrary variables via a query string that causes the variable to be defined in global space, with separate _GET, _REQUEST, or other critical parameters, which are unset by the protection scheme and prevent the original variable from being detected.

Affected (1)

1 product
Coppermine Photo Gallery
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.4.8_stable

Timeline

No history available yet.