---
cve: "CVE-2007-1107"
severity: "LOW"
cvss: 3.1
epss: "2.1%"
vendor: "n/a"
kev: false
exploited: false
published: "2007-02-26 17:28:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T03:41:27+02:00"
---

# CVE-2007-1107

> 3.1 LOW · 🧪 PoC

## Beschreibung

SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie.  NOTE: it was later reported that 1.4.10, 1.4.14, and other 1.4.x versions are also affected using similar cookies.

## Exploit-Evidenz

- [EDB-3371 — Coppermine Photo Gallery 1.3.x - Blind SQL Injection](https://www.exploit-db.com/exploits/3371) ✅

## Referenzen

- <http://www.securityfocus.com/archive/1/461158/100/0/threaded>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/32688>
- <http://securityreason.com/securityalert/2297>
- <http://www.securityfocus.com/bid/22709>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/39806>
- <https://www.exploit-db.com/exploits/3371>
- <https://www.exploit-db.com/exploits/4950>
- <http://www.securityfocus.com/bid/27372>
- <https://www.exploit-db.com/exploits/4961>
- <http://osvdb.org/33133>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2007-1107) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
