vendor:
Piwigo
by:
TaurusOmar
8,8
CVSS
HIGH
SQL Injection / Cross Site Scripting
89, 79
CWE
Product Name: Piwigo
Affected Version From: 2.7.2
Affected Version To: 2.7.2
Patch Exists: YES
Related CWE: CVE-2014-1470, CVE-2013-1468, CVE-2013-1469
CPE: 2.7.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Bugtraq Optimus
2014
Piwigo 2.7.2 – SQL Injection / Cross Site Scripting Vulnerability’s
Piwigo is a photo gallery software for the web that comes with powerful features to publish and manage your collection of pictures. Cross Site Scripting vulnerability can be exploited by entering malicious code in the box of group list. SQL Injection vulnerability can be exploited by entering malicious code in the control panel of admin and other users.
Mitigation:
Ensure that user input is validated and filtered before being used in SQL queries.