6
CVSSv2

CVE-2015-1517

Published: 20/02/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Piwigo prior to 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL commands via the filter_level parameter in a "Refresh photo set" action in the batch_manager page to admin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

piwigo piwigo

Exploits

[CVE-2015-1517] Piwigo - SQL Injection in Version 273 ---------------------------------------------------------------- Product Information: Software: Piwigo Tested Version: 273, released on 9 January 2015 Vulnerability Type: SQL Injection (CWE-89) Download link: piwigoorg/basics/downloads Description: Piwigo is photo gallery sof ...
Piwigo version 273 suffers from a remote SQL injection vulnerability ...