Description
WordPress Plugin Cool Video Gallery is prone to a command injection vulnerability because it fails to properly validate user-supplied input. An attacker can exploit this issue to execute arbitrary commands within the context of the vulnerable application. WordPress Plugin Cool Video Gallery version 1.9 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0 or latest
References
http://www.vapidlabs.com/advisory.php?v=158
http://www.openwall.com/lists/oss-security/2015/12/02/9
http://seclists.org/oss-sec/2015/q4/420
https://packetstormsecurity.com/files/134626/WordPress-Cool-Video-Gallery-1.9-Command-Injection.html
Related Vulnerabilities
WordPress Plugin WP Survey And Quiz Tool 'rowcount' Parameter Cross-Site Scripting (2.9.2)
WordPress Plugin WP Link To Us Multiple Cross-Site Scripting Vulnerabilities (2.0)
WordPress Plugin Blue Wrench Video Widget Cross-Site Scripting (2.1.0)
Oracle Database Server CVE-2008-2592 Vulnerability (CVE-2008-2592)