4.3
CVSSv2

CVE-2008-7175

Published: 08/09/2009 Updated: 11/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in NextGEN Gallery 0.96 and previous versions plugin for Wordpress allows remote malicious users to inject arbitrary web script or HTML via the picture description field in a page edit action.

Vulnerable Product Search on Vulmon Subscribe to Product

alex_rabe nextgen_gallery 0.95

alex_rabe nextgen_gallery 0.94

alex_rabe nextgen_gallery 0.80

alex_rabe nextgen_gallery 0.74

alex_rabe nextgen_gallery 0.62

alex_rabe nextgen_gallery 0.61

alex_rabe nextgen_gallery 0.41

alex_rabe nextgen_gallery 0.40

alex_rabe nextgen_gallery 0.83

alex_rabe nextgen_gallery 0.82

alex_rabe nextgen_gallery 0.81

alex_rabe nextgen_gallery 0.64

alex_rabe nextgen_gallery 0.63

alex_rabe nextgen_gallery 0.43

alex_rabe nextgen_gallery 0.42

alex_rabe nextgen_gallery 0.34

alex_rabe nextgen_gallery 0.33

alex_rabe nextgen_gallery

alex_rabe nextgen_gallery 0.93

alex_rabe nextgen_gallery 0.92

alex_rabe nextgen_gallery 0.73

alex_rabe nextgen_gallery 0.72

alex_rabe nextgen_gallery 0.60

alex_rabe nextgen_gallery 0.52

alex_rabe nextgen_gallery 0.39

alex_rabe nextgen_gallery 0.37

alex_rabe nextgen_gallery 0.91

alex_rabe nextgen_gallery 0.90

alex_rabe nextgen_gallery 0.71

alex_rabe nextgen_gallery 0.70

alex_rabe nextgen_gallery 0.51

alex_rabe nextgen_gallery 0.50

alex_rabe nextgen_gallery 0.36

alex_rabe nextgen_gallery 0.35