1 results (0.005 seconds)

CVSS: 6.1EPSS: 0%CPEs: 2EXPL: 4

Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery Plugin 3.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gid parameter. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en vodpod-video-gallery/vodpod_gallery_thumbs.php en el Plugin Vodpod Video Gallery v3.1.5 para WordPress, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del parámetro gid. Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery Plugin 3.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gid parameter. • https://www.exploit-db.com/exploits/34976 http://osvdb.org/69084 http://packetstormsecurity.org/1011-exploits/wpvodpod-xss.txt http://secunia.com/advisories/42195 http://securityreason.com/securityalert/8431 http://www.johnleitch.net/Vulnerabilities/WordPress.Vodpod.Video.Gallery.3.1.5.Reflected.Cross-site.Scripting/58 https://exchange.xforce.ibmcloud.com/vulnerabilities/63057 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •