MidnightBSD

Advisories for skyphe

CVE-2014-2558 MEDIUM

The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
skyphe file-gallery 1.4
skyphe file-gallery 1.5.1
skyphe file-gallery 1.6.5.3
skyphe file-gallery *
skyphe file-gallery 1.7.8
skyphe file-gallery 1.6.5.5
skyphe file-gallery 1.7.5.1
skyphe file-gallery 1.6.3
skyphe file-gallery 1.6.4
skyphe file-gallery 1.6.2
skyphe file-gallery 1.6.5.1
skyphe file-gallery 1.5.7
skyphe file-gallery 1.6.6
skyphe file-gallery 1.6.5
skyphe file-gallery 1.6.5.6
skyphe file-gallery 1.6.5.2
skyphe file-gallery 1.5.9
skyphe file-gallery 1.5.4
skyphe file-gallery 1.6
skyphe file-gallery 1.7.2
skyphe file-gallery 1.7.6
skyphe file-gallery 1.7.5.3
skyphe file-gallery 1.5.2
skyphe file-gallery 1.7.4.1
skyphe file-gallery 1.1
skyphe file-gallery 1.5.5
skyphe file-gallery 1.7
skyphe file-gallery 1.7.7
skyphe file-gallery 1.3
skyphe file-gallery 1.5.8
skyphe file-gallery 1.7.4
skyphe file-gallery 1.5.3
skyphe file-gallery 1.6.4.1
skyphe file-gallery 1.7.3
skyphe file-gallery 1.7.5
skyphe file-gallery 1.5
skyphe file-gallery 1.6.0.1
skyphe file-gallery 1.7.1
skyphe file-gallery 1.2
skyphe file-gallery 1.6.5.4
skyphe file-gallery 1.5.6
CVE-2023-48771

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruno "Aesqe" Babic File Gallery allows Reflected XSS.This issue affects File Gallery: from n/a through 1.8.5.4.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
audit@patchstack.com 7.1 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L 2.8 3.7
nvd@nist.gov 6.1 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 2.8 2.7

Products Affected

Vendor Product Version
skyphe file_gallery *