CVE-2017-10682
29.06.2017, 21:29
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.
Vendor | Product | Version |
---|---|---|
piwigo | piwigo | 𝑥 ≤ 2.9.1 |
𝑥
= Vulnerable software versions
References