CVE-2008-7175 describes a cross-site scripting (XSS) vulnerability in the NextGEN Gallery plugin (versions 0.96 and earlier) for WordPress. This flaw allows remote attackers to inject malicious web script or HTML into a website via the picture description field during a page edit action within the wp-admin/admin.php interface. The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and requiring no authentication, with a potential impact of partial integrity compromise. There is no evidence of active exploitation, no known exploit code available in common databases like Metasploit or ExploitDB, and it has received negligible community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.96CPE matchmatch criteria | cpe:2.3:a:alex_rabe:nextgen_gallery:*:*:*:*:*:*:*:* | ||
0.33CPE matchmatch criteria | cpe:2.3:a:alex_rabe:nextgen_gallery:0.33:*:*:*:*:*:*:* | ||
0.34CPE matchmatch criteria | cpe:2.3:a:alex_rabe:nextgen_gallery:0.34:*:*:*:*:*:*:* | ||
0.35CPE matchmatch criteria | cpe:2.3:a:alex_rabe:nextgen_gallery:0.35:*:*:*:*:*:*:* | ||
0.36CPE matchmatch criteria | cpe:2.3:a:alex_rabe:nextgen_gallery:0.36:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.