Back

CVE-2004-1989

PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.

Published: Apr 30, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (11)

Vendor Product Version
coppermine coppermine_photo_gallery 1.0_rc3
coppermine coppermine_photo_gallery 1.1_.0
coppermine coppermine_photo_gallery 1.1_beta_2
coppermine coppermine_photo_gallery 1.2
coppermine coppermine_photo_gallery 1.2.1
coppermine coppermine_photo_gallery 1.2.2_b
francisco_burzi php-nuke 6.9
francisco_burzi php-nuke 7.0
francisco_burzi php-nuke 7.0_final
francisco_burzi php-nuke 7.1
francisco_burzi php-nuke 7.2

GitHub Security Advisory GHSA-ph59-qghm-32cp

PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 9.33%

Top 5% most likely to be exploited

Threat Score 32.8 / 100

Data Sources

NVD EPSS GitHub