Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-9115
Description:SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.
Test IDs: 1.3.6.1.4.1.25623.1.0.805102  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-9115
http://seclists.org/fulldisclosure/2014/Nov/23




© 1998-2025 E-Soft Inc. All rights reserved.