CVE-2015-1517 Information

Description

SQL injection vulnerability in Piwigo before 2.7.4 when all filters are activated allows remote authenticated users to execute arbitrary SQL commands via the filter_level parameter in a \Refresh photo set\ action in the batch_manager page to admin.php.

Reference

http://packetstormsecurity.com/files/130440/Piwigo-2.7.3-SQL-Injection.html http://piwigo.org/forum/viewtopic.php?id=25179 http://piwigo.org/releases/2.7.4 http://www.securityfocus.com/archive/1/534723/100/0/threaded http://www.securityfocus.com/bid/72664

Share on: