Vulnerabilities
Fancy Gallery 1.5.12 Reflected XSS
$_GET['delete'] is not escaped.
20-11-2014
1 MIN READ
Vulnerabilities
$_GET['delete'] is not escaped.
1 MIN READ
Vulnerabilities
json_return() function doesn't check admin privileges.
1 MIN READ
Vulnerabilities
is_admin() function is used to check priveleges but because this code is run in context of wp-admin/admin-ajax.php this function always evalute to true.
1 MIN READ
Vulnerabilities
Datas from Open End questions are not escaped properly.
1 MIN READ
Vulnerabilities
REQUEST['src'] is passed directly into file_get_contents function.
1 MIN READ
Vulnerabilities
$_GET['gpid'] is not escaped.
1 MIN READ
Vulnerabilities
_form_makercfm() is accessible for every registered user.
1 MIN READ
Vulnerabilities
$_GET['searchll'] is not escaped.
1 MIN READ