CVE-2014-2558
06.05.2014, 14:55
The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.
| Vendor | Product | Version |
|---|---|---|
| skyphe | file-gallery | 𝑥 ≤ 1.7.9 |
| skyphe | file-gallery | 1.1 |
| skyphe | file-gallery | 1.2 |
| skyphe | file-gallery | 1.3 |
| skyphe | file-gallery | 1.4 |
| skyphe | file-gallery | 1.5 |
| skyphe | file-gallery | 1.5:a |
| skyphe | file-gallery | 1.5:b |
| skyphe | file-gallery | 1.5:b2 |
| skyphe | file-gallery | 1.5:b3 |
| skyphe | file-gallery | 1.5:rc1 |
| skyphe | file-gallery | 1.5.1 |
| skyphe | file-gallery | 1.5.2 |
| skyphe | file-gallery | 1.5.3 |
| skyphe | file-gallery | 1.5.4 |
| skyphe | file-gallery | 1.5.5 |
| skyphe | file-gallery | 1.5.6 |
| skyphe | file-gallery | 1.5.7 |
| skyphe | file-gallery | 1.5.8 |
| skyphe | file-gallery | 1.5.8:b1 |
| skyphe | file-gallery | 1.5.8:b2 |
| skyphe | file-gallery | 1.5.9 |
| skyphe | file-gallery | 1.6 |
| skyphe | file-gallery | 1.6.0.1 |
| skyphe | file-gallery | 1.6.2 |
| skyphe | file-gallery | 1.6.3 |
| skyphe | file-gallery | 1.6.4 |
| skyphe | file-gallery | 1.6.4.1 |
| skyphe | file-gallery | 1.6.5 |
| skyphe | file-gallery | 1.6.5.1 |
| skyphe | file-gallery | 1.6.5.2 |
| skyphe | file-gallery | 1.6.5.3 |
| skyphe | file-gallery | 1.6.5.4 |
| skyphe | file-gallery | 1.6.5.5 |
| skyphe | file-gallery | 1.6.5.6 |
| skyphe | file-gallery | 1.6.6:beta |
| skyphe | file-gallery | 1.7 |
| skyphe | file-gallery | 1.7:rc10 |
| skyphe | file-gallery | 1.7:rc11 |
| skyphe | file-gallery | 1.7:rc12 |
| skyphe | file-gallery | 1.7:rc13 |
| skyphe | file-gallery | 1.7:rc14 |
| skyphe | file-gallery | 1.7:rc3 |
| skyphe | file-gallery | 1.7:rc4 |
| skyphe | file-gallery | 1.7:rc5 |
| skyphe | file-gallery | 1.7:rc6 |
| skyphe | file-gallery | 1.7:rc7 |
| skyphe | file-gallery | 1.7:rc8 |
| skyphe | file-gallery | 1.7:rc9 |
| skyphe | file-gallery | 1.7.1 |
| skyphe | file-gallery | 1.7.2 |
| skyphe | file-gallery | 1.7.3 |
| skyphe | file-gallery | 1.7.4 |
| skyphe | file-gallery | 1.7.4:rc2 |
| skyphe | file-gallery | 1.7.4.1 |
| skyphe | file-gallery | 1.7.5 |
| skyphe | file-gallery | 1.7.5:beta1 |
| skyphe | file-gallery | 1.7.5:beta2 |
| skyphe | file-gallery | 1.7.5.1 |
| skyphe | file-gallery | 1.7.5.3 |
| skyphe | file-gallery | 1.7.6 |
| skyphe | file-gallery | 1.7.7 |
| skyphe | file-gallery | 1.7.8 |
𝑥
= Vulnerable software versions
References