PICA Photo Gallery <= 1.0 - SQL Injection
critical
The PICA Photo Gallery plugin for WordPress is vulnerable to SQL Injection via the ‘aid’ parameter in versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL...
- CVSS:
- 9.8
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 9, 2017
CVE-2017-20247 on NVD →
PICA Photo Gallery [pica-photo-gallery] <= 1.0 (unfixed)
unknown
The PICA Photo Gallery plugin for WordPress is vulnerable to SQL Injection via the ‘aid’ parameter in versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL...
- Affected:
- up to 1.0
- Fix:
- No patched version reported
- Disclosed:
- Mar 9, 2017
PICA Photo Gallery [pica-photo-gallery] < 1.1 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jul 27, 2016
PICA Photo Gallery [pica-photo-gallery] < 100 (unfixed + closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- Affected:
- up to 100
- Fix:
- No patched version reported
- Disclosed:
- Jul 19, 2013
CVE-2012-3414 on NVD →
SWFUpload <= 2.2.0.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
- CVSS:
- 6.1
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Nov 9, 2012
CVE-2012-3414 on NVD →
PICA Photo Gallery [pica-photo-gallery] < 1.1 (closed)
unknown
Pica Photo Gallery plugin is prone to an arbitrary file upload vulnerability. Restricted access to this script is not properly realized. In that way an attacker can to upload files containing malicious PHP code and run it in the context of the web server process. Other attacks are also possible.
Update the plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jun 11, 2012
PICA Photo Gallery [pica-photo-gallery] < 1.1 (closed)
unknown
WordPress Pica Photo Gallery plugin is prone to a remote file disclosure vulnerability. It allows an attacker to compromise encrypted login credentials for or retrieve the device's administrator password allowing them to directly access the device's configuration control panel.
Update the plugin.
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Jun 8, 2012
PICA Photo Gallery [pica-photo-gallery] <= 1.0 (unfixed + closed)
unknown
The pica-photo-gallery WordPress plugin was affected by an Arbitrary File Upload security vulnerability.
- Affected:
- up to 1.0
- Fix:
- No patched version reported
PICA Photo Gallery [pica-photo-gallery] <= 1.0 (unfixed + closed)
unknown
The pica-photo-gallery WordPress plugin was affected by a Remote File Disclosure security vulnerability.
- Affected:
- up to 1.0
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database