The File Gallery plugin prior to 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
skyphe file-gallery 1.7.2 |
||
skyphe file-gallery 1.7.1 |
||
skyphe file-gallery 1.7 |
||
skyphe file-gallery 1.6.5.5 |
||
skyphe file-gallery 1.6.6 |
||
skyphe file-gallery 1.6.5.4 |
||
skyphe file-gallery 1.6.5.3 |
||
skyphe file-gallery 1.5.7 |
||
skyphe file-gallery 1.5.6 |
||
skyphe file-gallery 1.5.5 |
||
skyphe file-gallery 1.5.4 |
||
skyphe file-gallery 1.7.5.3 |
||
skyphe file-gallery 1.7.5.1 |
||
skyphe file-gallery 1.7.5 |
||
skyphe file-gallery 1.6.3 |
||
skyphe file-gallery 1.6.2 |
||
skyphe file-gallery 1.6.0.1 |
||
skyphe file-gallery 1.6 |
||
skyphe file-gallery 1.5 |
||
skyphe file-gallery |
||
skyphe file-gallery 1.7.7 |
||
skyphe file-gallery 1.7.4.1 |
||
skyphe file-gallery 1.7.4 |
||
skyphe file-gallery 1.6.5.1 |
||
skyphe file-gallery 1.6.4.1 |
||
skyphe file-gallery 1.5.8 |
||
skyphe file-gallery 1.5.3 |
||
skyphe file-gallery 1.5.1 |
||
skyphe file-gallery 1.4 |
||
skyphe file-gallery 1.2 |
||
skyphe file-gallery 1.7.8 |
||
skyphe file-gallery 1.7.6 |
||
skyphe file-gallery 1.7.3 |
||
skyphe file-gallery 1.6.5.6 |
||
skyphe file-gallery 1.6.5.2 |
||
skyphe file-gallery 1.6.5 |
||
skyphe file-gallery 1.6.4 |
||
skyphe file-gallery 1.5.9 |
||
skyphe file-gallery 1.5.2 |
||
skyphe file-gallery 1.3 |
||
skyphe file-gallery 1.1 |