CVE-2016-10085: High severity piwigo vulnerability
Published Dec 30, 2016
·Updated
admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.
Affected Software
1 affected component
Piwigo piwigo<=2.8.3
Remediation
Event History
Dec 30, 2016
CVE Published
via MITRE·07:08 AM
Data Sourced
via MITRE·07:08 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10085?
CVE-2016-10085 is considered a medium severity vulnerability that allows for File Inclusion attacks.
2
How do I fix CVE-2016-10085?
To fix CVE-2016-10085, update Piwigo to version 2.8.4 or later, which addresses the vulnerability.
3
Who is affected by CVE-2016-10085?
CVE-2016-10085 affects remote authenticated administrators using vulnerable versions of Piwigo up to 2.8.3.
4
What type of vulnerability is CVE-2016-10085?
CVE-2016-10085 is classified as a Local File Inclusion (LFI) vulnerability.
5
What impact could CVE-2016-10085 have?
CVE-2016-10085 could allow an authenticated attacker to include arbitrary files on the server, potentially leading to data exposure.