Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-11018

Опубликовано: 21 янв. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:huge-it:image_gallery:*:*:*:*:*:wordpress:*:*
Версия до 1.9.0 (исключая)

EPSS

Процентиль: 78%
0.01138
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
больше 3 лет назад

An issue was discovered in the Huge-IT gallery-images plugin before 1.9.0 for WordPress. The headers Client-Ip and X-Forwarded-For are prone to unauthenticated SQL injection. The affected file is gallery-images.php. The affected function is huge_it_image_gallery_ajax_callback().

EPSS

Процентиль: 78%
0.01138
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89