Piwigo 'picture_modify.php' SQL Injection Vulnerability
BID:68142
Info
Piwigo 'picture_modify.php' SQL Injection Vulnerability
| Bugtraq ID: | 68142 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2014 12:00AM |
| Updated: | Jun 12 2014 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Piwigo Piwigo 2.3.4 Piwigo Piwigo 2.3.3 Piwigo Piwigo 2.3.2 Piwigo Piwigo 2.1.2 Piwigo Piwigo 2.0.9 Piwigo Piwigo 2.0.8 Piwigo Piwigo 2.0.7 Piwigo Piwigo 2.0.6 Piwigo Piwigo 2.0.5 Piwigo Piwigo 2.0.3 Piwigo Piwigo 2.0 |
| Not Vulnerable: | |
Discussion
Piwigo 'picture_modify.php' SQL Injection Vulnerability
Piwigo is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Piwigo versions prior to 2.7.0beta2 are vulnerable.
Piwigo is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Piwigo versions prior to 2.7.0beta2 are vulnerable.
Exploit / POC
Piwigo 'picture_modify.php' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Piwigo 'picture_modify.php' SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.