Description
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
Remediation
References
Related Vulnerabilities
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-8286)
WordPress Plugin Tutor LMS-eLearning and online course solution SQL Injection (2.6.1)
MySQL CVE-2013-3808 Vulnerability (CVE-2013-3808)
WordPress Plugin Search and Share Cross-Site Scripting (0.9.3)
Drupal Core 4.7.x Form Action Attribute Injection (4.7.0 - 4.7.3)