CVE-2014-2558
06.05.2014, 14:55
The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.
Vendor | Product | Version |
---|---|---|
skyphe | file-gallery | 𝑥 ≤ 1.7.9 |
skyphe | file-gallery | 1.1 |
skyphe | file-gallery | 1.2 |
skyphe | file-gallery | 1.3 |
skyphe | file-gallery | 1.4 |
skyphe | file-gallery | 1.5 |
skyphe | file-gallery | 1.5:a |
skyphe | file-gallery | 1.5:b |
skyphe | file-gallery | 1.5:b2 |
skyphe | file-gallery | 1.5:b3 |
skyphe | file-gallery | 1.5:rc1 |
skyphe | file-gallery | 1.5.1 |
skyphe | file-gallery | 1.5.2 |
skyphe | file-gallery | 1.5.3 |
skyphe | file-gallery | 1.5.4 |
skyphe | file-gallery | 1.5.5 |
skyphe | file-gallery | 1.5.6 |
skyphe | file-gallery | 1.5.7 |
skyphe | file-gallery | 1.5.8 |
skyphe | file-gallery | 1.5.8:b1 |
skyphe | file-gallery | 1.5.8:b2 |
skyphe | file-gallery | 1.5.9 |
skyphe | file-gallery | 1.6 |
skyphe | file-gallery | 1.6.0.1 |
skyphe | file-gallery | 1.6.2 |
skyphe | file-gallery | 1.6.3 |
skyphe | file-gallery | 1.6.4 |
skyphe | file-gallery | 1.6.4.1 |
skyphe | file-gallery | 1.6.5 |
skyphe | file-gallery | 1.6.5.1 |
skyphe | file-gallery | 1.6.5.2 |
skyphe | file-gallery | 1.6.5.3 |
skyphe | file-gallery | 1.6.5.4 |
skyphe | file-gallery | 1.6.5.5 |
skyphe | file-gallery | 1.6.5.6 |
skyphe | file-gallery | 1.6.6:beta |
skyphe | file-gallery | 1.7 |
skyphe | file-gallery | 1.7:rc10 |
skyphe | file-gallery | 1.7:rc11 |
skyphe | file-gallery | 1.7:rc12 |
skyphe | file-gallery | 1.7:rc13 |
skyphe | file-gallery | 1.7:rc14 |
skyphe | file-gallery | 1.7:rc3 |
skyphe | file-gallery | 1.7:rc4 |
skyphe | file-gallery | 1.7:rc5 |
skyphe | file-gallery | 1.7:rc6 |
skyphe | file-gallery | 1.7:rc7 |
skyphe | file-gallery | 1.7:rc8 |
skyphe | file-gallery | 1.7:rc9 |
skyphe | file-gallery | 1.7.1 |
skyphe | file-gallery | 1.7.2 |
skyphe | file-gallery | 1.7.3 |
skyphe | file-gallery | 1.7.4 |
skyphe | file-gallery | 1.7.4:rc2 |
skyphe | file-gallery | 1.7.4.1 |
skyphe | file-gallery | 1.7.5 |
skyphe | file-gallery | 1.7.5:beta1 |
skyphe | file-gallery | 1.7.5:beta2 |
skyphe | file-gallery | 1.7.5.1 |
skyphe | file-gallery | 1.7.5.3 |
skyphe | file-gallery | 1.7.6 |
skyphe | file-gallery | 1.7.7 |
skyphe | file-gallery | 1.7.8 |
𝑥
= Vulnerable software versions
References