Description
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.
Problem types
Unrestricted Upload of File with Dangerous Type
Product status
1.6.25
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51738
www.exploit-db.com/exploits/51738 (ExploitDB-51738)
web.archive.org/...101151648/https://coppermine-gallery.net/ (Coppermine Gallery Archived Product Webpage)
www.vulncheck.com/...remote-code-execution-via-plugin-upload
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.