Sploitus

CVE-2015-1517

3 known exploits for CVE-2015-1517

SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL commands via the filter_level parameter in a "Refresh photo set" action in the batch_manager page to admin.php.

Affected products
Piwigo
Piwigo
≤ 2.7.3
Fix
Available
CVSS 2.0
6.0 MEDIUM
EPSS
2.7% (85th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2015-02-20
CVE-2015-1517 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2015-1517

Proof-of-concept code and exploit modules indexed by Sploitus