7.5
CVSSv2

CVE-2014-9115

Published: 23/12/2014 Updated: 23/12/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo prior to 2.5.5, 2.6.x prior to 2.6.4, and 2.7.x prior to 2.7.2 allows remote malicious users to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

piwigo piwigo 2.6.2

piwigo piwigo 2.7.0

piwigo piwigo 2.7.1

piwigo piwigo

piwigo piwigo 2.6.0

piwigo piwigo 2.6.1

piwigo piwigo 2.6.3

Exploits

============================================= MGC ALERT 2014-001 - Original release date: January 12, 2014 - Last revised: November 12, 2014 - Discovered by: Manuel García Cárdenas - Severity: 7,1/10 (CVSS Base Score) ============================================= I VULNERABILITY ------------------------- Blind SQL Injection in Piwigo <= v2 ...