cleantalk
Vulnerabilities and Security Researches

Photo Gallery by 10Web – Mobile-Friendly Image Gallery, CVE-2015-1393

CVE, Research URL

CVE-2015-1393

Published on
Feb 02, 2015
Research Description
SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.
Affected versions
Min -, max 1.2.11.
Status
vulnerable