VulnerabilityModified
CVE-2015-2035
SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.
MEDIUM 6.5EPSS 1.81%
Does this matter?
Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- piwigo/piwigo
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/130432/CMS-Piwigo-2.7.3-Cross-Site-Scripting-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://piwigo.org/forum/viewtopic.php?id=25179Vendor Advisory
- http://piwigo.org/releases/2.7.4Patch, Release Notes, Vendor Advisory
- http://seclists.org/fulldisclosure/2015/Feb/73Exploit, Mailing List, Third Party Advisory
- http://sroesemann.blogspot.de/2015/01/sroeadv-2015-06.htmlNot Applicable
- http://sroesemann.blogspot.de/2015/02/report-for-advisory-sroeadv-2015-06.htmlNot Applicable
- http://www.securityfocus.com/bid/72689
- http://packetstormsecurity.com/files/130432/CMS-Piwigo-2.7.3-Cross-Site-Scripting-SQL-Injection.htmlExploit, Third Party Advisory, VDB Entry
- http://piwigo.org/forum/viewtopic.php?id=25179Vendor Advisory
- http://piwigo.org/releases/2.7.4Patch, Release Notes, Vendor Advisory
- http://seclists.org/fulldisclosure/2015/Feb/73Exploit, Mailing List, Third Party Advisory
- http://sroesemann.blogspot.de/2015/01/sroeadv-2015-06.htmlNot Applicable
- http://sroesemann.blogspot.de/2015/02/report-for-advisory-sroeadv-2015-06.htmlNot Applicable
- http://www.securityfocus.com/bid/72689
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.