CVE-2017-10682
CRITICALPiwigo < 2.9.1 - SQL Injection via cat_false or cat_true Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-10682. PoCs published by Akityo.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Piwigo's administrative backend via the 'cat_false' or 'cat_true' parameter in the comments or status page. The PoC provides a HTTP POST request template to exploit the vulnerability.
Description
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Piwigo's administrative backend via the 'cat_false' or 'cat_true' parameter in the comments or status page. The PoC provides a HTTP POST request template to exploit the vulnerability.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H