Record summary

CVE-2017-10682 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.

Description

SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBPiwigo 2.9.1 - 'cat_true' / 'cat_false' SQL InjectionExploitDB exploitby AkityoNot analyzed1 file
ExploitDB

PoC details

References

5