Vulnerabilities > Powerplay Gallery Project

DATE CVE VULNERABILITY TITLE RISK
2017-05-23 CVE-2015-5682 Permissions, Privileges, and Access Controls vulnerability in Powerplay Gallery Project Powerplay Gallery 3.3
upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.
network
low complexity
powerplay-gallery-project CWE-264
5.0
2015-08-18 CVE-2015-5599 SQL Injection vulnerability in Powerplay Gallery Project Powerplay Gallery 3.3
Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) albumid or (2) name parameter.
network
low complexity
powerplay-gallery-project CWE-89
7.5