7.5
CVSSv2

CVE-2019-14314

Published: 27/08/2019 Updated: 16/12/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A SQL injection vulnerability exists in the Imagely NextGEN Gallery plugin prior to 3.2.11 for WordPress. Successful exploitation of this vulnerability would allow a remote malicious user to execute arbitrary SQL commands on the affected system via modules/nextgen_gallery_display/package.module.nextgen_gallery_display.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imagely nextgen gallery

Github Repositories

CVE-2019-14314 - NextGEN Gallery 3.2.10 Authenticated SQL Injection

CVE-2019-14314 CVE-2019-14314 - NextGEN Gallery 3210 Authenticated SQL Injection Usage usage: cve_2019_14314py [-h] url login_user login_pass username CVE-2019-14314 Hash Extractor positional arguments: url Wordpress blog URL login_user Username to login with login_pass Password to login with username Username to extract Password Hash from optional ar