CVE-2016-10514: Medium severity Piwigo piwigo vulnerability
Published Oct 10, 2017
·Updated
urlcheckformat in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substring.
Affected Software
1 affected component
Piwigo piwigo<=2.8.2
Remediation
Patch Available
Patch Available
Event History
Oct 10, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10514?
CVE-2016-10514 is classified as a medium severity vulnerability.
2
How do I fix CVE-2016-10514?
To fix CVE-2016-10514, upgrade Piwigo to version 2.8.3 or later.
3
What software is affected by CVE-2016-10514?
CVE-2016-10514 affects Piwigo versions prior to 2.8.3.
4
What type of vulnerability is CVE-2016-10514?
CVE-2016-10514 allows remote attackers to bypass access restrictions.
5
Can CVE-2016-10514 be exploited via a specific type of URL?
Yes, CVE-2016-10514 can be exploited through URLs containing a " character or URLs that do not start with http:// or https://.