← Vulnerability feed

Vulnerability record · CVE-2008-3481 · published 5 August 2008

CVE-2008-3481: Coppermine-gallery coppermine photo gallery code injection vulnerability

Coppermine Gallery · Coppermine Photo Gallery

themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

7.5 CVSS 2.0 High EPSS 2.1% · top 18.9% CWE-94 · Code injection
7.5CVSS 2.0 base score
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-3481 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2023-53868Coppermine-gallery coppermine photo gallery unrestricted file upload vulnerabilityCoppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through th…EPSS 0.85%7.5CVE-2008-3486Coppermine-gallery coppermine photo gallery path traversal vulnerabilityDirectory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier,…EPSS 6.3%6.5CVE-2008-0504Coppermine-gallery coppermine photo gallery sql injection vulnerabilityMultiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary…EPSS 2.0%6.1CVE-2018-14478Coppermine-gallery coppermine photo gallery cross-site scripting vulnerabilityecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.EPSS 0.99%6.1CVE-2014-4612Coppermine-gallery coppermine photo gallery cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5.27 and 1.6.x before 1.6.01 a…EPSS 1.3%5.8CVE-2015-3922Coppermine-gallery coppermine photo gallery vulnerabilityOpen redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites an…EPSS 2.1%5.0CVE-2015-3923Coppermine-gallery coppermine photo gallery information exposure vulnerabilityCoppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate directories via a full path in the folder parameter to minibrowser.php.EPSS 2.2%5.0CVE-2012-1614Coppermine-gallery coppermine photo gallery information exposure vulnerabilityCoppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/…EPSS 8.7%

Source: NIST National Vulnerability Database (record CVE-2008-3481), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.