Vendor Site: http://www.zinkwazi.com/wp/scripts/ Version affected: 0.9.9.2 URL:http://www.example.com/scripts/demo/phpslideshow.php?directory=photos BID ref: 26576 By Jose Luis Góngora Fernández PHPSlideShow is also susceptible the following inputs: 1.http://www.yoursite.com/scripts/demo/phpslideshow.php?directory=">