CVE-2015-2035

NameCVE-2015-2035
DescriptionSQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
piwigosourcesqueeze(unfixed)end-of-life
piwigosource(unstable)(unfixed)

Notes

[squeeze] - piwigo <end-of-life> (Unsupported in squeeze-lts)
Request to mark the package as unsupported in #779104

Search for package or bug name: Reporting problems