SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2035
Reference (s):
- BID:72689
- URL: http://www.securityfocus.com/bid/72689
- http://piwigo.org/forum/viewtopic.php?id=25179
- http://piwigo.org/releases/2.7.4
- FULLDISC:20150218 Reflecting XSS- and SQL injection-vulnerabilities in the administrative backend of Piwigo <= v. 2.7.3

