SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | image_gallery | 1.0.1 |
XSS and SQLi in huge IT gallery v1.1.5 for Joomla
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 3.9 | 5.9 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | gallery | 1.1.5 |
XSS in huge IT gallery v1.1.5 for Joomla
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.1 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N | 2.8 | 2.7 |
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | gallery | 1.1.5 |
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | portfolio_gallery_manager | 1.1.0 |
Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | portfolio_gallery_manager | 1.1.5 |
XSS & SQLi in HugeIT slideshow v1.0.4
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | slideshow | 1.0.4 |
XSS & SQLi in HugeIT slideshow v1.0.4
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | slideshow | 1.0.4 |
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | catalog | 1.0.4 |
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | catalog | 1.0.4 |
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | slider | 1.0.9 |
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | slider | 1.0.9 |
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | video_gallery | 1.0.9 |
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | portfolio_gallery | 1.0.6 |
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
CVSS 2.0
Severity: HIGH
Problem Type: CWE-89,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| huge-it | huge-it_catalog | 1.0.7 |