SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2014-12-23T11:00:00
Updated: 2014-12-23T05:57:01
Reserved: 2014-11-26T00:00:00
Link: CVE-2014-9115
JSON object: View
NVD Information
Status : Analyzed
Published: 2014-12-23T11:59:04.110
Modified: 2014-12-23T19:12:08.460
Link: CVE-2014-9115
JSON object: View
Redhat Information
No data.
CWE