MidnightBSD

Advisories for huge-it

CVE-2014-7153 MEDIUM

SQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the removeslide parameter to wp-admin/admin.php.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
huge-it image_gallery 1.0.1
CVE-2016-1000113 HIGH

XSS and SQLi in huge IT gallery v1.1.5 for Joomla

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
huge-it gallery 1.1.5
CVE-2016-1000114 MEDIUM

XSS in huge IT gallery v1.1.5 for Joomla

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
huge-it gallery 1.1.5
CVE-2016-1000115 MEDIUM

Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-89,

Products Affected

Vendor Product Version
huge-it portfolio_gallery_manager 1.1.0
CVE-2016-1000116 MEDIUM

Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-89,

Products Affected

Vendor Product Version
huge-it portfolio_gallery_manager 1.1.5
CVE-2016-1000117 MEDIUM

XSS & SQLi in HugeIT slideshow v1.0.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-89,

Products Affected

Vendor Product Version
huge-it slideshow 1.0.4
CVE-2016-1000118 MEDIUM

XSS & SQLi in HugeIT slideshow v1.0.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-89,

Products Affected

Vendor Product Version
huge-it slideshow 1.0.4
CVE-2016-1000119 MEDIUM

SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,CWE-89,

Products Affected

Vendor Product Version
huge-it catalog 1.0.4
CVE-2016-1000120 MEDIUM

SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
huge-it catalog 1.0.4
CVE-2016-1000121 LOW

XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
huge-it slider 1.0.9
CVE-2016-1000122 MEDIUM

XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
huge-it slider 1.0.9
CVE-2016-1000123 HIGH

Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
huge-it video_gallery 1.0.9
CVE-2016-1000124 HIGH

Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
huge-it portfolio_gallery 1.0.6
CVE-2016-1000125 HIGH

Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
huge-it huge-it_catalog 1.0.7