Description
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2001-0004)
Apache Tomcat Other Vulnerability (CVE-2003-0042)
Apache HTTP Server Out-of-bounds Read Vulnerability (CVE-2026-33857)
Drupal Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2017-6928)
WordPress Plugin TagNinja 'id' Parameter Cross-Site Scripting (1.0)