Image Gallery with Slideshow <= 1.5.2 - SQL Injection via gallery_name
critical
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.5.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2017
CVE-2017-1002014 on NVD →
Image Gallery with Slideshow Plugin <= 1.5.2 - SQL Injection via gid
critical
The Image Gallery with Slideshow plugin for WordPress is vulnerable to generic SQL Injection via the ‘gid’ parameter in versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticat...
- CVSS:
- 9.8
- Affected:
- up to 1.5.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2017
CVE-2017-1002012 on NVD →
Image Gallery with Slideshow Plugin <= 1.5.2 - Blind SQL Injection via imgid
critical
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.
- CVSS:
- 9.8
- Affected:
- up to 1.5.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2017
CVE-2017-1002013 on NVD →
Image Gallery with Slideshow <= 1.5.2 - SQL Injection via selectMulGallery
critical
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.5.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2017
CVE-2017-1002015 on NVD →
Image Gallery with Slideshow Plugin <= 1.5.2 - Stored Cross-Site Scripting
medium
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database.
- CVSS:
- 5.4
- Affected:
- up to 1.5.2
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2017
CVE-2017-1002011 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database