Sploitus

CVE-2014-9115

2 known exploits for CVE-2014-9115

SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.

Affected products
Piwigo
Piwigo
≤ 2.5.5, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.7.0, 2.7.1
Fix
Available
CVSS 2.0
7.5 HIGH
EPSS
2.7% (85th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2014-12-23
CVE-2014-9115 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2014-9115

Proof-of-concept code and exploit modules indexed by Sploitus