CVE-2017-17827
- EPSS 0.17%
- Veröffentlicht 21.12.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions.
CVE-2017-17775
- EPSS 0.24%
- Veröffentlicht 20.12.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.
CVE-2017-17774
- EPSS 0.12%
- Veröffentlicht 20.12.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
admin/configuration.php in Piwigo 2.9.2 has CSRF.
CVE-2017-16893
- EPSS 0.16%
- Veröffentlicht 01.12.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve da...
CVE-2016-10514
- EPSS 0.29%
- Veröffentlicht 10.10.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substrin...
CVE-2016-10513
- EPSS 0.36%
- Veröffentlicht 10.10.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php.
CVE-2017-10682
- EPSS 0.32%
- Veröffentlicht 29.06.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.
CVE-2017-10681
- EPSS 0.18%
- Veröffentlicht 29.06.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to unlock albums via a crafted request.
CVE-2017-10680
- EPSS 0.18%
- Veröffentlicht 29.06.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request.
CVE-2017-10679
- EPSS 0.32%
- Veröffentlicht 29.06.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album. The permalink ID number...