SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2014-12-23T11:00:00

Updated: 2014-12-23T05:57:01

Reserved: 2014-11-26T00:00:00


Link: CVE-2014-9115

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-12-23T11:59:04.110

Modified: 2014-12-23T19:12:08.460


Link: CVE-2014-9115

JSON object: View

cve-icon Redhat Information

No data.

CWE