CVE-2015-7527
Summary
| CVE | CVE-2015-7527 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-12-17 19:59:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via shell metacharacters in the "Width of preview image" and possibly other input fields in the "Video Gallery Settings" page. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cool Video Gallery Project | Cool Video Gallery | 1.9 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - Command Injection in cool-video-gallery v1.9 Wordpress plugin | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Exploit |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.vapidlabs.com | Exploit |
| WordPress Cool Video Gallery 1.9 Command Injection ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit |
| Command Injection vulnerability in v1.9 | WordPress.org | af854a3a-2127-422b-91ae-364da2661108 | wordpress.org | Exploit |
| Cool Video Gallery <= 1.9 - Authenticated Comm& Injection | af854a3a-2127-422b-91ae-364da2661108 | wpvulndb.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.