Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sat, 6 Oct 2012 10:34:26 +0300
From: Henri Salo <>
Cc: Josh Bressers <>,
	Kurt Seifried <>,,
	coley <>
Subject: CVE-request for piwigo issues (second request)


Old CVE-request did not get filled. At least the CVE is not listed in Mitre's list, OSVDB, Secunia or Debian security-tracker. Request done in:

a1) CSRF
a2) SQL injection
a3) stored XSS
(the issues mentioned by the exploit-db entry appear to be the same that 
were fixed in 2.1.3)
b) search.php SQL injection
c) CSRF in the admin panel:
(the exploit-db entry details two other issues, but are "admin-only" -- feel 
free to assign or ignore those.)

SA41365: 2010
SA38305: 2010
SA37681: 2009

I am happy to provide more information if needed (or in clearner format). Please double-verify that these haven't been assigned before you assign IDs, please.

- Henri Salo

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ