CVE-2015-2035
Piwigo < 2.7.3 - Authenticated SQL Injection via User Parameter in History Page
Title source: llmDescription
SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.
References (7)
Core 7
Core References
Not Applicable x_refsource_misc
http://sroesemann.blogspot.de/2015/01/sroeadv-2015-06.html
Exploit, Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Feb/73
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/130432/CMS-Piwigo-2.7.3-Cross-Site-Scripting-SQL-Injection.html
Patch, Release Notes, Vendor Advisory x_refsource_confirm
http://piwigo.org/releases/2.7.4
Vendor Advisory x_refsource_confirm
http://piwigo.org/forum/viewtopic.php?id=25179
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/72689
Not Applicable x_refsource_misc
http://sroesemann.blogspot.de/2015/02/report-for-advisory-sroeadv-2015-06.html
Scores
EPSS
0.0181
EPSS Percentile
76.3%
Details
CWE
CWE-89
Status
published
Products (1)
piwigo/piwigo
< 2.7.3
Published
Feb 20, 2015
Tracked Since
Feb 18, 2026