Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
SHARE

CORE IMPACT v10 - Exploits Update (Tue Apr 13 2010)

Wordpress NextGEN Gallery Plugin Cross Site Scripting Exploit

Exploits/Cross Site Scripting (XSS)/Known Vulnerabilities  []




• Tue Apr 13 2010
This vulnerability results from a reflected unsanitized input that can be crafted into an attack by a malicious user by manipulating the 'mode' parameter of the xml/media-rss.php script. Version 1.5.1 is verified as vulnerable, older versions are probably vulnerable too but they were not tested at this time.

Exploits Vulnerabiltiy: CVE-2010-1186



< Back to Product Updates