Description
WordPress Plugin Cool Video Gallery is prone to a command injection vulnerability because it fails to properly validate user-supplied input. An attacker can exploit this issue to execute arbitrary commands within the context of the vulnerable application. WordPress Plugin Cool Video Gallery version 1.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0 or latest
References
http://www.vapidlabs.com/advisory.php?v=158
http://www.openwall.com/lists/oss-security/2015/12/02/9
http://seclists.org/oss-sec/2015/q4/420
https://packetstormsecurity.com/files/134626/WordPress-Cool-Video-Gallery-1.9-Command-Injection.html
Related Vulnerabilities
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-9048)
WordPress Plugin Search Exclude Security Bypass (1.2.2)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-2890)
OpenSSL Integer Overflow or Wraparound Vulnerability (CVE-2016-2177)