Show filters
109 Total Results
Displaying 61-70 of 109
Sort by:
Attacker Value
Unknown
CVE-2017-1002011
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database.
0
Attacker Value
Unknown
CVE-2017-1002014
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.
0
Attacker Value
Unknown
CVE-2016-4987
Disclosure Date: February 09, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields.
0
Attacker Value
Unknown
CVE-2015-1000007
Disclosure Date: October 06, 2016 (last updated November 25, 2024)
Remote file download vulnerability in wptf-image-gallery v1.03
0
Attacker Value
Unknown
CVE-2016-11018
Disclosure Date: May 11, 2016 (last updated February 21, 2025)
An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().
0
Attacker Value
Unknown
CVE-2014-7153
Disclosure Date: September 22, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.
0
Attacker Value
Unknown
CVE-2012-5304
Disclosure Date: October 06, 2012 (last updated October 05, 2023)
Static code injection vulnerability in administration/install.php in YVS Image Gallery allows remote attackers to inject arbitrary PHP code into functions/db_connect.php via unspecified vectors. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation.
0
Attacker Value
Unknown
CVE-2012-1564
Disclosure Date: October 06, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in administration/create_album.php in YVS Image Gallery allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2010-0979
Disclosure Date: March 16, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.
0
Attacker Value
Unknown
CVE-2009-4569
Disclosure Date: January 05, 2010 (last updated October 04, 2023)
SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/.
0