4.3
CVSSv2

CVE-2019-16118

Published: 08/09/2019 Updated: 23/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin prior to 1.5.35 for WordPress exists via admin/controllers/Options.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

10web photo gallery

Exploits

# Exploit Title: WordPress Plugin Photo Gallery by 10Web <= 1534 - Persistent Cross Site Scripting # inurl:"\wp-content\plugins\photo-gallery" # Date: 09-10-2019 # Exploit Author: MTK (mtk911cf/) # Vendor Homepage: 10webio/ # Software Link: downloadswordpressorg/plugin/photo-gallery1534zip # Version: Up to v153 ...
WordPress Photo Gallery plugin version 1534 suffers from multiple cross site scripting vulnerabilities ...

Github Repositories

Desarrollo del CTF EVM1

EVM1 Desarrollo del CTF EVM1 1 Configuración de la VM Download VM: wwwvulnhubcom/entry/evm-1,391/ La VM no funciona en VMWARE WORKSTATION (la interfaz de red no funciona) Solo funciona en VIRTUALBOX 2 Escaneo de Puertos Nmap 791 scan initiated Tue Apr 20 09:32:39 2021 as: nmap -n -P0 -p- -sS -sC -sV -vv -T5 -oA full 19216856103 Nmap scan report for 19