CVE-2016-6565
Last modified
CVE-2016-6565 is a vulnerability of currently unknown severity. The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).. EPSS estimates a 2.54% chance of exploitation in the next 30 days.
Description
The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cssfile parameter of a HTTP POST request, which may allow an authenticated user to read arbitrary files from the server, or execute arbitrary code on the server in some circumstances (dependent on server configuration).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Imagely | Nextgen Gallery | < 2.1.57 |
References
- https://www.kb.cert.org/vuls/id/346175Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/94356/Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/346175Third Party Advisory, US Government Resource
- https://www.securityfocus.com/bid/94356/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-6565?
How severe is CVE-2016-6565?
How do I fix CVE-2016-6565?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-6559Improper bounds checking of the obuf variable in the link_nt…
- CVE-2016-6560illumos osnet-incorporation bcopy() and bzero() implementati…
- CVE-2016-6561illumos smbsrv NULL pointer dereference allows system crash.
- CVE-2016-6562On iOS and Android devices, the ShoreTel Mobility Client app…
- CVE-2016-6563Processing malformed SOAP messages when performing the HNAP …
- CVE-2016-6564Android devices with code from Ragentek contain a privileged…
- CVE-2016-6566The valueAsString parameter inside the JSON payload containe…
- CVE-2016-6567SHDesigns' Resident Download Manager provides firmware updat…
- CVE-2016-6578CodeLathe FileCloud, version 13.0.0.32841 and earlier, conta…8.8
- CVE-2016-6579Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-6580A HTTP/2 implementation built using any version of the Pytho…
- CVE-2016-6581A HTTP/2 implementation built using any version of the Pytho…
Are you affected by CVE-2016-6565?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
