Coppermine Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2012-1614 - Vulnerability Database

Coppermine Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2012-1614

Medium
Reference: CVE-2012-1614
Title: Coppermine Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php an invalid (2) page or (3) cat parameter to thumbnails.php an invalid (4) page parameter to usermgr.php or an invalid (5) newer_than or (6) older_than parameter to search.inc.php which reveals the installation path in an error message.