CVE-2006-6123 describes a vulnerability in Coppermine Photo Gallery (CPG) 1.4.8 stable when PHP's register_globals is enabled. This flaw allows remote attackers to bypass existing cross-site scripting (XSS) protection mechanisms. Attackers can achieve this by manipulating query string parameters, causing critical variables to be defined in the global scope and preventing the XSS protection from detecting the original malicious input. The vulnerability has a CVSS score of 2.6, indicating a low severity. It is a network-based attack with high access complexity, requiring no authentication, and primarily impacts data integrity (partial). There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting a low level of public awareness and interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.8_stableCPE matchmatch criteria | cpe:2.3:a:coppermine:coppermine_photo_gallery:1.4.8_stable:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.