CVE-2008-7175: XSS
Published Sep 8, 2009
·Updated
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in NextGEN Gallery 0.96 and earlier plugin for Wordpress allows remote attackers to inject arbitrary web script or HTML via the picture description field in a page edit action.
Affected Software
35 affected components
Alex Rabe Nextgen Gallery<=0.96
Alex Rabe Nextgen Gallery=0.33
Alex Rabe Nextgen Gallery=0.34
Alex Rabe Nextgen Gallery=0.35
Alex Rabe Nextgen Gallery=0.36
Alex Rabe Nextgen Gallery=0.37
Alex Rabe Nextgen Gallery=0.39
Alex Rabe Nextgen Gallery=0.40
Alex Rabe Nextgen Gallery=0.41
Alex Rabe Nextgen Gallery=0.42
Alex Rabe Nextgen Gallery=0.43
Alex Rabe Nextgen Gallery=0.50
Alex Rabe Nextgen Gallery=0.51
Alex Rabe Nextgen Gallery=0.52
Alex Rabe Nextgen Gallery=0.60
Alex Rabe Nextgen Gallery=0.61
Alex Rabe Nextgen Gallery=0.62
Alex Rabe Nextgen Gallery=0.63
Alex Rabe Nextgen Gallery=0.64
Alex Rabe Nextgen Gallery=0.70
Alex Rabe Nextgen Gallery=0.71
Alex Rabe Nextgen Gallery=0.72
Alex Rabe Nextgen Gallery=0.73
Alex Rabe Nextgen Gallery=0.74
Alex Rabe Nextgen Gallery=0.80
Alex Rabe Nextgen Gallery=0.81
Alex Rabe Nextgen Gallery=0.82
Alex Rabe Nextgen Gallery=0.83
Alex Rabe Nextgen Gallery=0.90
Alex Rabe Nextgen Gallery=0.91
Alex Rabe Nextgen Gallery=0.92
Alex Rabe Nextgen Gallery=0.93
Alex Rabe Nextgen Gallery=0.94
Alex Rabe Nextgen Gallery=0.95
WordPress
Event History
Sep 8, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
10:30 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-7175?
CVE-2008-7175 has a moderate severity rating due to its ability to allow cross-site scripting attacks.
2
How do I fix CVE-2008-7175?
To fix CVE-2008-7175, update the NextGEN Gallery plugin to version 0.97 or later.
3
What versions of NextGEN Gallery are affected by CVE-2008-7175?
CVE-2008-7175 affects NextGEN Gallery versions 0.96 and earlier.
4
What type of vulnerability is CVE-2008-7175?
CVE-2008-7175 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2008-7175 allow attackers to access user data?
Yes, CVE-2008-7175 can allow attackers to inject arbitrary web scripts or HTML, potentially compromising user data.