CVE-2015-2035 Information
Feb 14, 2021
cve
Description
SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.
Reference
http://packetstormsecurity.com/files/130432/CMS-Piwigo-2.7.3-Cross-Site-Scripting-SQL-Injection.html http://piwigo.org/forum/viewtopic.php?id=25179 http://piwigo.org/releases/2.7.4 http://seclists.org/fulldisclosure/2015/Feb/73 http://sroesemann.blogspot.de/2015/01/sroeadv-2015-06.html http://sroesemann.blogspot.de/2015/02/report-for-advisory-sroeadv-2015-06.html http://www.securityfocus.com/bid/72689
Share on: