S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2011-4624 Scanner

CVE-2011-4624 scanner - Cross-Site Scripting (XSS) vulnerability in GRAND FlAGallery

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2011-4624
4.3
CVSS

Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

GRAND FlAGallery is a popular plugin used by WordPress users who want to add Flash photo galleries to their website. This plugin includes features like advanced gallery management, multiple gallery layouts, and easy customization, which makes it an essential tool for website owners who want to enhance the visual appeal of their site. The plugin is widely used by photographers, designers, and creative professionals who want to showcase their work online.

The CVE-2011-4624 vulnerability detected in this plugin refers to a Cross-Site Scripting (XSS) flaw in the facebook.php file of GRAND FlAGallery. This vulnerability makes it possible for hackers to inject arbitrary web scripts or HTML code using the i parameter, which can be exploited to steal sensitive data or initiate malicious activities on the website. This vulnerability affects versions of the plugin prior to 1.57.

When this vulnerability is exploited, it can lead to several malicious activities such as stealing user credentials, hijacking user sessions, delivering malware, and bypassing security controls. It can also lead to damaging the reputation of the website, impacting user trust, and causing significant financial losses. As such, it's important to fix this vulnerability as soon as possible to prevent the potential consequences.

At S4E, we provide comprehensive security solutions for businesses and individuals looking to safeguard their digital assets. Our platform offers pro features that can quickly detect and report vulnerabilities in your website or web application. By subscribing to our service, you can be assured that your website is secure and protected against any potential threats. Don't wait until it's too late, sign up for S4E today!

 

REFERENCES

Solution Advice

There are several precautions that website owners can take to protect against the CVE-2011-4624 vulnerability in GRAND FlAGallery:

  • Update to the latest version of the plugin - Disable the i parameter in the facebook.php file
  • Use a web application firewall to block malicious traffic
  • Regularly monitor and audit your website for any vulnerabilities
  • Educate your website users about the potential risks of XSS attacks and how to prevent them

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2011-4624 scanner - Cross-Site Scripting (XSS) vulnerability in GRAND FlAGallery | S4E