cleantalk
Vulnerabilities and Security Researches

Gmedia Photo Gallery, CVE-2015-4339

CVE, Research URL

CVE-2015-4339

Application

Gmedia Photo Gallery

Published on
-
Research Description
The Gmedia Photo Gallery plugin for WordPress is vulnerable to Open Proxy attacks in versions up to, and including, 1.6.4. This is due to inclusion of a script intended to load images from a url that doesn't end in an image file extension. This makes it possible for unauthenticated attackers to proxy through the server and perform anonymized attacks on other servers.
Affected versions
max 1.6.5.
Status
vulnerable