Vulnerabilities > John Bradshaw

DATE CVE VULNERABILITY TITLE RISK
2011-11-02 CVE-2010-5041 SQL Injection vulnerability in John Bradshaw NP Gallery Plugin 0.94
SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action.
network
low complexity
john-bradshaw nucleuscms CWE-89
7.5
2011-11-02 CVE-2010-5040 Code Injection vulnerability in John Bradshaw NP Gallery Plugin 0.94
PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary PHP code via a URL in the DIR_NUCLEUS parameter.
6.8