Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-344w-5936-x3fq

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.

SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.

EPSS

Процентиль: 68%
0.00579
Низкий

Дефекты

CWE-89

Связанные уязвимости

ubuntu
около 11 лет назад

SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.

nvd
около 11 лет назад

SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.

debian
около 11 лет назад

SQL injection vulnerability in the rate_picture function in include/fu ...

EPSS

Процентиль: 68%
0.00579
Низкий

Дефекты

CWE-89