plugin

Pica Photo Gallery Vulnerabilities

9 known security issues reported for the Pica Photo Gallery WordPress plugin. Most recent disclosed Mar 9, 2017.

1 critical 1 medium

Running Pica Photo Gallery on your site? Check whether your installed version is affected.

Scan your site free

PICA Photo Gallery <= 1.0 - SQL Injection

critical

The PICA Photo Gallery plugin for WordPress is vulnerable to SQL Injection via the ‘aid’ parameter in versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL...

CVSS:
9.8
Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Mar 9, 2017

CVE-2017-20247 on NVD →

PICA Photo Gallery [pica-photo-gallery] <= 1.0 (unfixed)

unknown

The PICA Photo Gallery plugin for WordPress is vulnerable to SQL Injection via the ‘aid’ parameter in versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL...

Affected:
up to 1.0
Fix:
No patched version reported
Disclosed:
Mar 9, 2017

PICA Photo Gallery [pica-photo-gallery] < 1.1 (closed)

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jul 27, 2016

PICA Photo Gallery [pica-photo-gallery] < 100 (unfixed + closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

Affected:
up to 100
Fix:
No patched version reported
Disclosed:
Jul 19, 2013

CVE-2012-3414 on NVD →

SWFUpload <= 2.2.0.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.

CVSS:
6.1
Affected:
up to *
Fix:
No patched version reported
Disclosed:
Nov 9, 2012

CVE-2012-3414 on NVD →

PICA Photo Gallery [pica-photo-gallery] < 1.1 (closed)

unknown

Pica Photo Gallery plugin is prone to an arbitrary file upload vulnerability. Restricted access to this script is not properly realized. In that way an attacker can to upload files containing malicious PHP code and run it in the context of the web server process. Other attacks are also possible. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jun 11, 2012

PICA Photo Gallery [pica-photo-gallery] < 1.1 (closed)

unknown

WordPress Pica Photo Gallery plugin is prone to a remote file disclosure vulnerability. It allows an attacker to compromise encrypted login credentials for or retrieve the device's administrator password allowing them to directly access the device's configuration control panel. Update the plugin.

Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Jun 8, 2012

PICA Photo Gallery [pica-photo-gallery] <= 1.0 (unfixed + closed)

unknown

The pica-photo-gallery WordPress plugin was affected by an Arbitrary File Upload security vulnerability.

Affected:
up to 1.0
Fix:
No patched version reported

PICA Photo Gallery [pica-photo-gallery] <= 1.0 (unfixed + closed)

unknown

The pica-photo-gallery WordPress plugin was affected by a Remote File Disclosure security vulnerability.

Affected:
up to 1.0
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database