9.8
CVSSv3

CVE-2021-24139

Published: 18/03/2021 Updated: 22/03/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unvalidated input in the Photo Gallery (10Web Photo Gallery) WordPress plugin, versions prior to 1.5.55, leads to SQL injection via the frontend/models/model.php bwg_search_x parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

10web photo gallery

Github Repositories

Desarrollo del CTF EVM1

EVM1 Desarrollo del CTF EVM1 1 Configuración de la VM Download VM: wwwvulnhubcom/entry/evm-1,391/ La VM no funciona en VMWARE WORKSTATION (la interfaz de red no funciona) Solo funciona en VIRTUALBOX 2 Escaneo de Puertos Nmap 791 scan initiated Tue Apr 20 09:32:39 2021 as: nmap -n -P0 -p- -sS -sC -sV -vv -T5 -oA full 19216856103 Nmap scan report for 19