6.5
CVSSv2

CVE-2014-2558

Published: 06/05/2014 Updated: 07/05/2014
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The File Gallery plugin prior to 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.

Vulnerable Product Search on Vulmon Subscribe to Product

skyphe file-gallery 1.7.2

skyphe file-gallery 1.7.1

skyphe file-gallery 1.7

skyphe file-gallery 1.6.5.5

skyphe file-gallery 1.6.6

skyphe file-gallery 1.6.5.4

skyphe file-gallery 1.6.5.3

skyphe file-gallery 1.5.7

skyphe file-gallery 1.5.6

skyphe file-gallery 1.5.5

skyphe file-gallery 1.5.4

skyphe file-gallery 1.7.5.3

skyphe file-gallery 1.7.5.1

skyphe file-gallery 1.7.5

skyphe file-gallery 1.6.3

skyphe file-gallery 1.6.2

skyphe file-gallery 1.6.0.1

skyphe file-gallery 1.6

skyphe file-gallery 1.5

skyphe file-gallery

skyphe file-gallery 1.7.7

skyphe file-gallery 1.7.4.1

skyphe file-gallery 1.7.4

skyphe file-gallery 1.6.5.1

skyphe file-gallery 1.6.4.1

skyphe file-gallery 1.5.8

skyphe file-gallery 1.5.3

skyphe file-gallery 1.5.1

skyphe file-gallery 1.4

skyphe file-gallery 1.2

skyphe file-gallery 1.7.8

skyphe file-gallery 1.7.6

skyphe file-gallery 1.7.3

skyphe file-gallery 1.6.5.6

skyphe file-gallery 1.6.5.2

skyphe file-gallery 1.6.5

skyphe file-gallery 1.6.4

skyphe file-gallery 1.5.9

skyphe file-gallery 1.5.2

skyphe file-gallery 1.3

skyphe file-gallery 1.1