CVE-2010-1186
NextGEN Gallery < 1.5.2 - Cross-Site Scripting via mode Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1186. PoCs published by Alejandro Rodriguez.
AI-analyzed exploit summary This advisory describes a reflected XSS vulnerability in the NextGEN Gallery WordPress plugin (versions 1.5.0 and 1.5.1) due to unsanitized input in the 'mode' parameter of the media-rss.php script. The proof of concept demonstrates the vulnerability via a crafted URL.
Description
Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode parameter.
Exploits (1)
This advisory describes a reflected XSS vulnerability in the NextGEN Gallery WordPress plugin (versions 1.5.0 and 1.5.1) due to unsanitized input in the 'mode' parameter of the media-rss.php script. The proof of concept demonstrates the vulnerability via a crafted URL.