Gmedia Photo Gallery, CVE-2015-4339
- CVE, Research URL
- Home page URL
- Application
- Published on
- -
- Research Description
- The Gmedia Photo Gallery plugin for WordPress is vulnerable to Open Proxy attacks in versions up to, and including, 1.6.4. This is due to inclusion of a script intended to load images from a url that doesn't end in an image file extension. This makes it possible for unauthenticated attackers to proxy through the server and perform anonymized attacks on other servers.
- Affected versions
-
max 1.6.5.
- Status
-
vulnerable