security issue in 1.4.9? security issue in 1.4.9?
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

security issue in 1.4.9?

Started by François Keller, October 28, 2006, 08:18:00 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

François Keller

Hi,

This link was post on french board:
http://www.milw0rm.com/exploits/2660
Is this a real security problem on Coppermine 1.4.9 ?
Avez vous lu la DOC ? la FAQ ? et cherché sur le forum avant de poster ?
Did you read the DOC ? the FAQ ? and search the board before posting ?
Mon Blog

Aditya Mooley

Yes, it is an exploit.

Till the time we release a new security update, users can manually fix this as follows:

Open picmgr.php
Somewhere near line 353
find:

$aid = isset($_GET['aid']) ? ($_GET['aid']) : 0;


replace with

$aid = isset($_GET['aid']) ? (int)($_GET['aid']) : 0;
--- "Its Nice 2 BE Important but its more Important 2 Be NICE" ---
Follow Coppermine on Twitter

François Keller

Ok thank's for replay, i'll post your fix in the french board
Avez vous lu la DOC ? la FAQ ? et cherché sur le forum avant de poster ?
Did you read the DOC ? the FAQ ? and search the board before posting ?
Mon Blog

Joachim Müller

cpg1.4.10 has been released to address the issue - see announcement thread.