NA

CVE-2022-2190

Published: 31/10/2022 Updated: 01/11/2022
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Gallery Plugin for WordPress plugin prior to 1.8.4.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

enviragallery envira gallery

Github Repositories

CVE-2022-21907: detection, protection, exploitation and demonstration. Exploitation: Powershell, Python, Ruby, NMAP and Metasploit. Detection and protection: Powershell. Demonstration: Youtube.

CVE-2022-21907 Description This repository detects a system vulnerable to CVE-2022-21907 (CVSS:31 98) and protects against this vulnerability if desired I offer 2 powershell codes in 1 line I propose pure python, powershell, ruby scripts and metasploit, nmap modules to attack a vulnerable IIS Web Server (perform a DOS attack to crash (blue screen) the server) Detection a