Description
admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosure and code execution if it contains a .. sequence.
Remediation
References
Related Vulnerabilities
WordPress Plugin WPS Hide Login Cross-Site Request Forgery (1.0)
WordPress Plugin WordPress Photo Gallery by Gallery Bank Cross-Site Scripting (3.0.69)
MySQL CVE-2015-0508 Vulnerability (CVE-2015-0508)
WordPress Plugin Simple Sitemap-Create a Responsive HTML Sitemap Cross-Site Scripting (3.5.7)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-6897)