Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8234-r487-52gh

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.

include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.

EPSS

Процентиль: 99%
0.88385
Высокий

Дефекты

CWE-20

Связанные уязвимости

nvd
около 18 лет назад

include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php.

EPSS

Процентиль: 99%
0.88385
Высокий

Дефекты

CWE-20