CVE-2017-10682
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.
- Affected products
- Piwigo
- Piwigo
- ≤ 2.9.1
- Fix
- Available
- CVSS 3.0
- 9.8 CRITICAL
- EPSS
- 8.3% (95th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2017-06-29
CVE-2017-10682 at NVD
4 known exploits for CVE-2017-10682
Proof-of-concept code and exploit modules indexed by Sploitus