CVE-2014-4649: SQL Injection
Published Jun 28, 2014
·Updated
SQL injection vulnerability in the photo-edit subsystem in Piwigo 2.6.x and 2.7.x before 2.7.0beta2 allows remote authenticated administrators to execute arbitrary SQL commands via the associate[] field.
Affected Software
5 affected components
Piwigo piwigo=2.6.0
Piwigo piwigo=2.6.1
Piwigo piwigo=2.6.2
Piwigo piwigo=2.6.3
Piwigo piwigo=2.7.0-beta1
Event History
Jun 28, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4649?
CVE-2014-4649 is classified as a medium severity SQL injection vulnerability.
2
How do I fix CVE-2014-4649?
To fix CVE-2014-4649, upgrade Piwigo to version 2.7.0 beta2 or later.
3
Who is affected by CVE-2014-4649?
CVE-2014-4649 affects remote authenticated administrators using Piwigo versions 2.6.x and 2.7.0 beta1.
4
What can attackers do with CVE-2014-4649?
Attackers can execute arbitrary SQL commands via the associate[] field due to the SQL injection vulnerability in CVE-2014-4649.
5
Is CVE-2014-4649 still a threat?
CVE-2014-4649 poses a threat if vulnerable versions of Piwigo are still in use and not updated.