CVE-2016-6565
Last modified
CVE-2016-6565 is a vulnerability of currently unknown severity. The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).. EPSS estimates a 2.54% chance of exploitation in the next 30 days.
Description
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Imagely | Nextgen Gallery | < 2.1.57 |
References
- https://www.kb.cert.org/vuls/id/346175Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/94356/Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/346175Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/94356/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-6565?
How severe is CVE-2016-6565?
How do I fix CVE-2016-6565?
Are you affected by CVE-2016-6565?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
