Title : Coppermine Photo Gallery "usermgr.php" Script Privilege Escalation Vulnerability VUPEN ID : VUPEN/ADV-2006-2185 CVE ID : CVE-2006-2976
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-06-07
Technical Description
A vulnerability has been identified in Coppermine Photo Gallery, which may be exploited by malicious users to bypass security restrictions and obtain elevated privileges. This flaw is due to an error in the "usermgr.php" script that does not check user privileges before granting access to restricted management options, which could be exploited by malicious users to perfom administrative tasks (e.g. edit a user profile) on a vulnerable application.