Page 9 of 43 results (0.007 seconds)

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php. Vulnerabilidad de inyección SQL en el plugin Photo Gallery 1.2.7 para WordPress permite a atacantes remotos ejecutar comandos SQL arbitrarios a través del parámetro order_by en una acción GalleryBox en wp-admin/admin-ajax.php. • http://seclists.org/fulldisclosure/2015/Jan/36 http://www.securityfocus.com/bid/72015 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

The photo-gallery plugin before 1.2.42 for WordPress has CSRF. El plugin photo-gallery anterior a la versión 1.2.42 para WordPress tiene CSRF. The Photo Gallery plugin before 1.2.42 for WordPress has CSRF. • https://wordpress.org/plugins/photo-gallery/#developers https://wordpress.org/support/topic/this-plugin-is-reported-as-vulnerable https://wpvulndb.com/vulnerabilities/7225 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 2

Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id parameter to gallery_photo.php, and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of these details are obtained from third party information. Múltiples vulnerabilidades de inyección SQL en DevelopItEasy Photo Gallery v1.2 permite a atacantes remotos ejecutar comandos SQL de su elección mediante (1) el parámetro "cat_id2 en gallery_category.php, los parámetros (2) "photo_id" y (4) "user_pass" en admin/index.php. NOTA: algunos de estos detalles se han obtenido de información de terceros. • https://www.exploit-db.com/exploits/7016 http://secunia.com/advisories/32593 http://www.securityfocus.com/bid/32145 https://exchange.xforce.ibmcloud.com/vulnerabilities/46400 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •