cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forreflex-gallery reflex-gallery

Direction: ascending
Jun 06, 2024

ReFlex Gallery » WordPress Photo Gallery # CVE-2015-4133

CVE, Research URL

CVE-2015-4133

Date
May 28, 2015
Research Description
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.
Affected versions
Min -, max -.
Status
vulnerable

ReFlex Gallery » WordPress Photo Gallery # CVE-2013-7482

CVE, Research URL

CVE-2013-7482

Date
Aug 22, 2019
Research Description
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
Affected versions
Min -, max -.
Status
vulnerable

ReFlex Gallery » WordPress Photo Gallery # CVE-2013-6837

CVE, Research URL

CVE-2013-6837

Date
Dec 19, 2013
Research Description
Cross-site scripting (XSS) vulnerability in the setTimeout function in js/jquery.prettyPhoto.js in prettyPhoto 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted PATH_INTO to the default URI.
Affected versions
Min -, max -.
Status
vulnerable