Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-6565

Опубликовано: 13 июл. 2018
Источник: nvd
CVSS3: 7.5
CVSS2: 6
EPSS Низкий

Описание

The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:imagely:nextgen_gallery:*:*:*:*:*:wordpress:*:*
Версия до 2.1.57 (исключая)

EPSS

Процентиль: 81%
0.01515
Низкий

7.5 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-98
CWE-20

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).

EPSS

Процентиль: 81%
0.01515
Низкий

7.5 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-98
CWE-20