CVE-2017-10682: SQL Injection
Published Jun 29, 2017
·Updated
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the catfalse or cattrue parameter in the comments or status page to catoptions.php.
Affected Software
1 affected component
Piwigo piwigo<=2.9.1
Remediation
Event History
Jun 29, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10682?
CVE-2017-10682 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2017-10682?
To fix CVE-2017-10682, update Piwigo to version 2.9.2 or later.
3
What software is affected by CVE-2017-10682?
CVE-2017-10682 affects Piwigo versions up to and including 2.9.1.
4
Can CVE-2017-10682 be exploited remotely?
Yes, CVE-2017-10682 allows remote users to execute arbitrary SQL commands.
5
What parameters are involved in the exploitation of CVE-2017-10682?
The parameters involved in the exploitation of CVE-2017-10682 are cat_false and cat_true.