MySliderGallery <= 1.2.1 - Remote File Inclusion
criticalPHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.2.1 and earlier plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the myPath parameter. Note that this uses the same slug as a newer plugin that is not vulnerable.
- CVSS:
- 9.8
- Affected:
- up to 1.2.1
- Fixed in:
- 1.4b5
- Disclosed:
- Apr 29, 2007