Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 06:53:42 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1848398544&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F1002-exploits%2Fcoppermine_piceditor.rb.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1848398544.1338188022.1338188022.1338188022.1%3B%2B__utmz%3D32867617.1338188022.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) Coppermine Photo Gallery 1.4.14 picEditor.php Command Execution http://packetstormsecurity.org/files/86501/coppermine_piceditor.rb.txt http://packetstormsecurity.org/files/86501/coppermine_piceditor.rb.txt http://packetstormsecurity.org/files/86501/Coppermine-Photo-Gallery-1.4.14-picEditor.php-Command-Execution.html Sat, 20 Feb 2010 19:41:10 GMT This Metasploit module exploits a vulnerability in the picEditor.php script of Coppermine Photo Gallery. When configured to use the ImageMagick library, the 'quality', 'angle', and 'clipval' parameters are not properly escaped before being passed. NOTE: Use of the ImageMagick library is a non-default option. However, a user can specify its use at installation time.