HTTP: Piwigo Cross Site Scripting

This signature detects attempts to exploit a known vulnerability against Piwigo. A successful attack can lead to Cross Site Scripting and SQL injection.

Extended Description

SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.

Affected Products

Piwigo piwigo

Short Name
HTTP:PHP:PIWIGO-XSS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2015-2034 CVE-2015-2035 Cross Piwigo Scripting Site bid:72690
Release Date
05/22/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Piwigo

CVSS Score

6.5

4.3

Found a potential security threat?