PT-2011-1810 · Vodpod · Vodpod Video Gallery Plugin

John Leitch

·

Published

2011-10-07

·

Updated

2017-08-29

·

CVE-2010-4875

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Vodpod Video Gallery Plugin version 3.1.5
Description The issue is related to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary web script or HTML via the gid parameter in the vodpod-gallery/vodpod gallery thumbs.php file.
Recommendations For Vodpod Video Gallery Plugin version 3.1.5, avoid using the gid parameter in the vulnerable file until the issue is resolved. Consider temporarily restricting access to the vodpod-gallery/vodpod gallery thumbs.php file to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4875

Affected Products

Vodpod Video Gallery Plugin