CVE-2008-7175

Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in NextGEN Gallery 0.96 and earlier plugin for Wordpress allows remote attackers to inject arbitrary web script or HTML via the picture description field in a page edit action.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
alex_rabenextgen_gallery
𝑥
≤ 0.96
alex_rabenextgen_gallery
0.33
alex_rabenextgen_gallery
0.34
alex_rabenextgen_gallery
0.35
alex_rabenextgen_gallery
0.36
alex_rabenextgen_gallery
0.37
alex_rabenextgen_gallery
0.39
alex_rabenextgen_gallery
0.40
alex_rabenextgen_gallery
0.41
alex_rabenextgen_gallery
0.42
alex_rabenextgen_gallery
0.43
alex_rabenextgen_gallery
0.50
alex_rabenextgen_gallery
0.51
alex_rabenextgen_gallery
0.52
alex_rabenextgen_gallery
0.60
alex_rabenextgen_gallery
0.61
alex_rabenextgen_gallery
0.62
alex_rabenextgen_gallery
0.63
alex_rabenextgen_gallery
0.64
alex_rabenextgen_gallery
0.70
alex_rabenextgen_gallery
0.71
alex_rabenextgen_gallery
0.72
alex_rabenextgen_gallery
0.73
alex_rabenextgen_gallery
0.74
alex_rabenextgen_gallery
0.80
alex_rabenextgen_gallery
0.81
alex_rabenextgen_gallery
0.82
alex_rabenextgen_gallery
0.83
alex_rabenextgen_gallery
0.90
alex_rabenextgen_gallery
0.91
alex_rabenextgen_gallery
0.92
alex_rabenextgen_gallery
0.93
alex_rabenextgen_gallery
0.94
alex_rabenextgen_gallery
0.95
𝑥
= Vulnerable software versions