Show filters
88 Total Results
Displaying 71-80 of 88
Sort by:
Attacker Value
Unknown
CVE-2015-2034
Disclosure Date: February 20, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter to admin.php.
0
Attacker Value
Unknown
CVE-2015-1517
Disclosure Date: February 20, 2015 (last updated October 05, 2023)
SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL commands via the filter_level parameter in a "Refresh photo set" action in the batch_manager page to admin.php.
0
Attacker Value
Unknown
CVE-2015-2035
Disclosure Date: February 20, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.
0
Attacker Value
Unknown
CVE-2015-1441
Disclosure Date: February 03, 2015 (last updated October 05, 2023)
SQL injection vulnerability in Piwigo before 2.5.6, 2.6.x before 2.6.5, and 2.7.x before 2.7.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-9115
Disclosure Date: December 23, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.
0
Attacker Value
Unknown
CVE-2014-3900
Disclosure Date: August 17, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in admin/picture_modify.php in the photo-edit subsystem in Piwigo 2.6.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the associate[] field, a different vulnerability than CVE-2014-4649.
0
Attacker Value
Unknown
CVE-2014-1980
Disclosure Date: August 14, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in include/functions_metadata.inc.php in Piwigo before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the Make field in IPTC Exif metadata within an image uploaded to the Community plugin.
0
Attacker Value
Unknown
CVE-2014-4614
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Piwigo before 2.6.2 allow remote attackers to hijack the authentication of administrators for requests that use the (1) pwg.groups.addUser, (2) pwg.groups.deleteUser, (3) pwg.groups.setInfo, (4) pwg.users.setInfo, (5) pwg.permissions.add, or (6) pwg.permissions.remove method.
0
Attacker Value
Unknown
CVE-2014-4649
Disclosure Date: June 28, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the photo-edit subsystem in Piwigo 2.6.x and 2.7.x before 2.7.0beta2 allows remote authenticated administrators to execute arbitrary SQL commands via the associate[] field.
0
Attacker Value
Unknown
CVE-2014-4648
Disclosure Date: June 28, 2014 (last updated October 05, 2023)
Unspecified vulnerability in Piwigo before 2.6.3 has unknown impact and attack vectors, related to a "security failure."
0