PoC Index

CVE-2015-2035

MEDIUM 6.5EPSS 1.8%

SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.

CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
1.81% chance of exploitation in the next 30 days, 77th percentile
Published
2015-02-20
Updated
2024-08-06

Proof-of-concept exploits (1)

References

Related