CVE Database /
CVE-2016-6565
CVE · High
CVE-2016-6565 — Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.57
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2016-6565, CVE-2016-10889
|
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 2.1.57 |
Improper Input Validation |
High
7.5
|
< 2.1.57
|
2.1.57 |
2016-11-15 |
—
|
CVE-2016-6565, CVE-2016-10889
The Imagely NextGen Gallery plugin before version 2.1.57 contains insufficient input validation on the cssfile parameter when processing HTTP POST requests, potentially enabling authenticated users to read sensitive files from the server or execute arbitrary code depending on how the server is configured.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings