Unrated severityNVD Advisory· Published Feb 20, 2015· Updated May 6, 2026
CVE-2015-2035
CVE-2015-2035
Description
SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- piwigo.org/releases/2.7.4nvdPatchRelease NotesVendor Advisory
- packetstormsecurity.com/files/130432/CMS-Piwigo-2.7.3-Cross-Site-Scripting-SQL-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2015/Feb/73nvdExploitMailing ListThird Party Advisory
- piwigo.org/forum/viewtopic.phpnvdVendor Advisory
- sroesemann.blogspot.de/2015/01/sroeadv-2015-06.htmlnvdNot Applicable
- sroesemann.blogspot.de/2015/02/report-for-advisory-sroeadv-2015-06.htmlnvdNot Applicable
- www.securityfocus.com/bid/72689nvd
News mentions
0No linked articles in our index yet.