CVE-2017-17823
- EPSS 0.33%
- Veröffentlicht 21.12.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Configuration component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/configuration.php order_by array parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
CVE-2017-17824
- EPSS 0.33%
- Veröffentlicht 21.12.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Batch Manager component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/batch_manager_unit.php element_ids parameter in unit mode. An attacker can exploit this to gain access to the data in a connected MySQL database.
CVE-2017-17825
- EPSS 0.24%
- Veröffentlicht 21.12.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a client's browser along with the da...
CVE-2017-17826
- EPSS 0.24%
- Veröffentlicht 21.12.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=configuration§ion=main request. An attacker can exploit this to hijack a client's browser along with...
CVE-2017-17827
- EPSS 0.17%
- Veröffentlicht 21.12.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions.
CVE-2017-17774
- EPSS 0.12%
- Veröffentlicht 20.12.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
admin/configuration.php in Piwigo 2.9.2 has CSRF.
CVE-2017-17775
- EPSS 0.24%
- Veröffentlicht 20.12.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.
CVE-2017-16893
- EPSS 0.16%
- Veröffentlicht 01.12.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve da...
CVE-2016-10513
- EPSS 0.36%
- Veröffentlicht 10.10.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php.
CVE-2016-10514
- EPSS 0.29%
- Veröffentlicht 10.10.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substrin...