CVE-2014-9115

NameCVE-2014-9115
DescriptionSQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
piwigosourcesqueeze(unfixed)end-of-life
piwigosource(unstable)(unfixed)

Notes

[squeeze] - piwigo <end-of-life> (Unsupported in squeeze-lts)
Request to mark the package as unsupported in #779104

Search for package or bug name: Reporting problems