// For flags

CVE-2008-7175

NextGEN Gallery Plugin <= 1.9.0 - Authenticated (Admin+) Stored Cross-Site Scripting

Severity Score

4.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in NextGEN Gallery 0.96 and earlier plugin for Wordpress allows remote attackers to inject arbitrary web script or HTML via the picture description field in a page edit action.

Una vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados(XSS) en wp-admin/admin.php en el plugin NextGEN Gallery v0.96 y anteriores para Wordpress permite a atacantes remotos inyectar HTML o secuencias de comandos web a través del campo de descripción de la imagen en una acción de edición de página.

The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description field for galleries in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

*Credits: Eduardo Neves a.k.a _eth0_
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-06-07 CVE Published
  • 2009-09-07 CVE Reserved
  • 2023-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
<= 0.96
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version " <= 0.96"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.33
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.33"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.34
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.34"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.35
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.35"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.36
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.36"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.37
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.37"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.39
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.39"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.40
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.40"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.41
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.41"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.42
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.42"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.43
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.43"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.50
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.50"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.51
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.51"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.52
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.52"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.60
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.60"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.61
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.61"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.62
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.62"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.63
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.63"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.64
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.64"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.70
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.70"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.71
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.71"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.72
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.72"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.73
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.73"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.74
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.74"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.80
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.80"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.81
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.81"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.82
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.82"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.83
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.83"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.90
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.90"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.91
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.91"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.92
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.92"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.93
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.93"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.94
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.94"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe
Alex Rabe
Search vendor "Alex Rabe"
Nextgen Gallery
Search vendor "Alex Rabe" for product "Nextgen Gallery"
0.95
Search vendor "Alex Rabe" for product "Nextgen Gallery" and version "0.95"
-
Affected
in Wordpress
Search vendor "Wordpress"
Wordpress
Search vendor "Wordpress" for product "Wordpress"
*-
Safe