The vulnerability was produced by inefficient patch for CVE-2008-1840
Vulnerability details
Advisory: SB2008041401 - SQL injection in Coppermine Photo Gallery
Vulnerable component: Coppermine Photo Gallery
CVE-ID: CVE-2008-1841
CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:F/RL:O/RC:C
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description:
The vulnerability allows a remote attacker to execute arbitrary SQL commands in web application database.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via cookies to "coppermine.inc.php" script. A remote attacker can send a specially crafted HTTP request to vulnerable script and execute arbitrary SQL queries in backend database.
Successful exploitation of the vulnerability may result in website compromise.
Note: this vulnerability was being actively exploited.
External links:
https://secur1ty.com/cve/CVE-2008-1841/
http://www.securityfocus.com/bid/28767
http://www.xatrix.org/cve-vulns/CVE-2008-1841-c40321/
https://www.vulnerabilitycenter.com/#!vul=18228
http://cve.scap.org.cn/CVE-2008-1841.html
https://www.security-database.com/detail.php?alert=CVE-2008-1841
http://forum.coppermine-gallery.net/index.php/topic,51882.0.html