All Video Gallery Plugin for WordPress [all-video-gallery] < 1.2.0 (closed)
unknown
[en] Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors.
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
- Disclosed:
- Aug 6, 2014
CVE-2012-6653 on NVD →
All Video Gallery Plugin for WordPress [all-video-gallery] <= 1.2 (closed)
unknown
[en] SQL injection vulnerability in the All Video Gallery (all-video-gallery) plugin 1.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in an edit action in the allvideogallery_videos page to wp-admin/admin.php.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Aug 6, 2014
CVE-2014-5186 on NVD →
All Video Gallery Plugin for WordPress <= 1.2 - Authenticated SQL Injection
high
SQL injection vulnerability in the All Video Gallery (all-video-gallery) plugin 1.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in an edit action in the allvideogallery_videos page to wp-admin/admin.php.
- CVSS:
- 7.2
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- May 28, 2014
CVE-2014-5186 on NVD →
All Video Gallery <= 1.1 - SQL Injection
high
The All Video Gallery plugin for WordPress is vulnerable to blind SQL Injection via the ‘ vid’ and 'pid' parameters in versions up to, and including, 1.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated...
- CVSS:
- 7.3
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Nov 2, 2012
CVE-2012-6653 on NVD →
All Video Gallery Plugin for WordPress [all-video-gallery] <= 1.1 (unfixed + closed)
unknown
The all-video-gallery WordPress plugin was affected by a Multiple SQL Injection Vulnerabilities security vulnerability.
- Affected:
- up to 1.1
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database