CVE-2014-4649
Piwigo 2.6.x and 2.7.x < 2.7.0beta2 - Authenticated SQL Injection via Photo-Edit Associate Field
Title source: llmDescription
SQL injection vulnerability in the photo-edit subsystem in Piwigo 2.6.x and 2.7.x before 2.7.0beta2 allows remote authenticated administrators to execute arbitrary SQL commands via the associate[] field.
References (2)
Core 2
Core References
Various Sources x_refsource_confirm
http://piwigo.org/bugs/view.php?id=3089
Various Sources x_refsource_confirm
http://piwigo.org/bugs/changelog_page.php
Scores
EPSS
0.0101
EPSS Percentile
59.4%
Details
CWE
CWE-89
Status
published
Products (5)
piwigo/piwigo
2.6.0
piwigo/piwigo
2.6.1
piwigo/piwigo
2.6.2
piwigo/piwigo
2.6.3
piwigo/piwigo
2.7.0 beta1
Published
Jun 28, 2014
Tracked Since
Feb 18, 2026