SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL commands via the filter_level parameter in a “Refresh photo set” action in the batch_manager page to admin.php.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1517
Reference (s):
- BID:72664
- URL: http://www.securityfocus.com/bid/72664
- BUGTRAQ:20150218 [CVE-2015-1517] Piwigo – SQL Injection in Version 2.7.3
- URL: http://www.securityfocus.com/archive/1/534723/100/0/threaded
- http://piwigo.org/forum/viewtopic.php?id=25179