« Volver al listado

CVE-2015-3634

Estado: ModificadaAlta (7.5)—

The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2015-3634",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-06-08T21:29:00.347",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/05/02/12",
      "tags": [
        "Mailing List",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/74453",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/Boonstra/Slideshow/commit/cac505e593cbe70a4d8af5b639f5385d4cc7aa04",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://wordpress.org/plugins/slideshow-jquery-image-gallery/#developers",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2015/05/02/12",
      "tags": [
        "Mailing List",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/74453",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/Boonstra/Slideshow/commit/cac505e593cbe70a4d8af5b639f5385d4cc7aa04",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wordpress.org/plugins/slideshow-jquery-image-gallery/#developers",
      "tags": [
        "Release Notes",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values."
    },
    {
      "lang": "es",
      "value": "La función SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX en el plugin Slideshow, versiones de la 2.2.8 a la 2.2.21 parar Wordpress permite a atacantes remotos leer valores de opciones de WordPress arbitrarias."
    }
  ],
  "lastModified": "2026-06-17T00:26:00.977",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.8:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D693AA5-CEE2-4B0D-810C-6856718FC413"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.9:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12B5E530-2CB7-449D-8506-0D9B083585EF"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.10:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59BBB132-15D5-40CF-9C57-A5B2A3460754"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.11:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78B4DB44-5833-4FDC-8B69-0AC4AE9D27E8"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.12:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C3423BDE-F0EC-428C-AD2D-1F3FE18F0CA3"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.13:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58719E22-CC54-4C1B-908D-BE8C47B2D0C0"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.14:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A9417C40-C73D-4278-861A-253621C72FBC"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.15:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7013D864-5EB7-4331-977B-650F8E176D6C"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.16:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E521983-2FB1-441A-8C58-B467D4E72731"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.17:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56A4DF60-BF1E-4301-AC18-DC7145D30A88"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.18:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "603ECBA5-BCC7-43B1-8D3C-66D81A272F37"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.19:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "07D60CFA-A52A-4745-A07E-DDCAA8E6865C"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.20:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AC721B3-C4FB-43A7-8708-95EDD8A5FEDE"
            },
            {
              "criteria": "cpe:2.3:a:slideshow_project:slideshow:2.2.21:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E7B7A3F-2DF6-492F-9D16-3F8D56FBAAF9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}