Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.140626
Kategorie:Web application abuses
Titel:Piwigo Multiple Vulnerabilities
Zusammenfassung:Piwigo is prone to multiple vulnerabilities.
Beschreibung:Summary:
Piwigo is prone to multiple vulnerabilities.

Vulnerability Insight:
Piwigo is prone to multiple vulnerabilities:

- admin/configuration.php has a CSRF. (CVE-2017-17774)

- XSS via the name parameter in an admin.php?page=album-3-properties request. (CVE-2017-17775)

- Persistent XSS via the gallery_title parameter in an admin.php?page=configuration§ion=main request. An
attacker can exploit this to hijack a client's browser along with the data stored in it. (CVE-2017-17826)

- Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or
/admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing
unintended actions. (CVE-2017-17827)

- SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain
access to the data in a connected MySQL database. (CVE-2017-17822)

- SQL Injection via the admin/configuration.php order_by array parameter. An attacker can exploit this to gain
access to the data in a connected MySQL database. (CVE-2017-17823)

- SQL Injection via the admin/batch_manager_unit.php element_ids parameter in unit mode. An attacker can exploit
this to gain access to the data in a connected MySQL database. (CVE-2017-17824)

- Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit
request. An attacker can exploit this to hijack a client's browser along with the data stored in it.
(CVE-2017-17825)

Affected Software/OS:
Piwigo version 2.9.2 and probably prior.

Solution:
Update to version 2.9.3 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2017-17774
Common Vulnerability Exposure (CVE) ID: CVE-2017-17775
Common Vulnerability Exposure (CVE) ID: CVE-2017-17826
Common Vulnerability Exposure (CVE) ID: CVE-2017-17827
Common Vulnerability Exposure (CVE) ID: CVE-2017-17822
Common Vulnerability Exposure (CVE) ID: CVE-2017-17823
Common Vulnerability Exposure (CVE) ID: CVE-2017-17824
Common Vulnerability Exposure (CVE) ID: CVE-2017-17825
CopyrightCopyright (C) 2017 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.