Published: 23/12/2014 Updated: 23/12/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo prior to 2.5.5, 2.6.x prior to 2.6.4, and 2.7.x prior to 2.7.2 allows remote malicious users to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

piwigo piwigo 2.6.2

piwigo piwigo 2.7.0

piwigo piwigo 2.7.1

piwigo piwigo

piwigo piwigo 2.6.0

piwigo piwigo 2.6.1

piwigo piwigo 2.6.3


============================================= MGC ALERT 2014-001 - Original release date: January 12, 2014 - Last revised: November 12, 2014 - Discovered by: Manuel García Cárdenas - Severity: 7,1/10 (CVSS Base Score) ============================================= I VULNERABILITY ------------------------- Blind SQL Injection in Piwigo <= v2 ...