CVE-2015-2035

Piwigo < 2.7.3 - Authenticated SQL Injection via User Parameter in History Page

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.

References (7)

Core 7
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Feb/73
Patch, Release Notes, Vendor Advisory x_refsource_confirm
http://piwigo.org/releases/2.7.4
Vendor Advisory x_refsource_confirm
http://piwigo.org/forum/viewtopic.php?id=25179
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/72689

Scores

EPSS 0.0181
EPSS Percentile 76.3%

Details

CWE
CWE-89
Status published
Products (1)
piwigo/piwigo < 2.7.3
Published Feb 20, 2015
Tracked Since Feb 18, 2026