← Vulnerability feed

Vulnerability record · CVE-2015-3922 · published 27 May 2015

CVE-2015-3922: Coppermine-gallery coppermine photo gallery vulnerability

Coppermine Gallery · Coppermine Photo Gallery

Open redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter.

5.8 CVSS 2.0 Medium EPSS 2.1% · top 19.4%
5.8CVSS 2.0 base score
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Open redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter.

AV:N/AC:M/Au:N/C:P/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-3922 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2023-53868Coppermine-gallery coppermine photo gallery unrestricted file upload vulnerabilityCoppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through th…EPSS 0.85%7.5CVE-2008-3486Coppermine-gallery coppermine photo gallery path traversal vulnerabilityDirectory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier,…EPSS 6.3%7.5CVE-2008-3481Coppermine-gallery coppermine photo gallery code injection vulnerabilitythemes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct req…EPSS 2.1%6.5CVE-2008-0504Coppermine-gallery coppermine photo gallery sql injection vulnerabilityMultiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary…EPSS 2.0%6.1CVE-2018-14478Coppermine-gallery coppermine photo gallery cross-site scripting vulnerabilityecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.EPSS 0.99%6.1CVE-2014-4612Coppermine-gallery coppermine photo gallery cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5.27 and 1.6.x before 1.6.01 a…EPSS 1.3%5.0CVE-2015-3923Coppermine-gallery coppermine photo gallery information exposure vulnerabilityCoppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate directories via a full path in the folder parameter to minibrowser.php.EPSS 2.2%5.0CVE-2012-1614Coppermine-gallery coppermine photo gallery information exposure vulnerabilityCoppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/…EPSS 8.7%

Source: NIST National Vulnerability Database (record CVE-2015-3922), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.