CVE-2014-2558

The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
VendorProductVersion
skyphefile-gallery
𝑥
≤ 1.7.9
skyphefile-gallery
1.1
skyphefile-gallery
1.2
skyphefile-gallery
1.3
skyphefile-gallery
1.4
skyphefile-gallery
1.5
skyphefile-gallery
1.5:a
skyphefile-gallery
1.5:b
skyphefile-gallery
1.5:b2
skyphefile-gallery
1.5:b3
skyphefile-gallery
1.5:rc1
skyphefile-gallery
1.5.1
skyphefile-gallery
1.5.2
skyphefile-gallery
1.5.3
skyphefile-gallery
1.5.4
skyphefile-gallery
1.5.5
skyphefile-gallery
1.5.6
skyphefile-gallery
1.5.7
skyphefile-gallery
1.5.8
skyphefile-gallery
1.5.8:b1
skyphefile-gallery
1.5.8:b2
skyphefile-gallery
1.5.9
skyphefile-gallery
1.6
skyphefile-gallery
1.6.0.1
skyphefile-gallery
1.6.2
skyphefile-gallery
1.6.3
skyphefile-gallery
1.6.4
skyphefile-gallery
1.6.4.1
skyphefile-gallery
1.6.5
skyphefile-gallery
1.6.5.1
skyphefile-gallery
1.6.5.2
skyphefile-gallery
1.6.5.3
skyphefile-gallery
1.6.5.4
skyphefile-gallery
1.6.5.5
skyphefile-gallery
1.6.5.6
skyphefile-gallery
1.6.6:beta
skyphefile-gallery
1.7
skyphefile-gallery
1.7:rc10
skyphefile-gallery
1.7:rc11
skyphefile-gallery
1.7:rc12
skyphefile-gallery
1.7:rc13
skyphefile-gallery
1.7:rc14
skyphefile-gallery
1.7:rc3
skyphefile-gallery
1.7:rc4
skyphefile-gallery
1.7:rc5
skyphefile-gallery
1.7:rc6
skyphefile-gallery
1.7:rc7
skyphefile-gallery
1.7:rc8
skyphefile-gallery
1.7:rc9
skyphefile-gallery
1.7.1
skyphefile-gallery
1.7.2
skyphefile-gallery
1.7.3
skyphefile-gallery
1.7.4
skyphefile-gallery
1.7.4:rc2
skyphefile-gallery
1.7.4.1
skyphefile-gallery
1.7.5
skyphefile-gallery
1.7.5:beta1
skyphefile-gallery
1.7.5:beta2
skyphefile-gallery
1.7.5.1
skyphefile-gallery
1.7.5.3
skyphefile-gallery
1.7.6
skyphefile-gallery
1.7.7
skyphefile-gallery
1.7.8
𝑥
= Vulnerable software versions