Category Archives: Security

viruskiller

Important security update!

Lazyest Gallery 1.0.29 or lower contains two potentially unsafe vulnerabilities.
The image popup script in lazyest-popup.php could allow cross site scripting. This vulnerability is found by High-Tech Bridge SA and they qualified it as a medium risk vulnerability.
The image processor for on-the-fly image creation could allow people to find the absolute path in which the plugin is installed. This vulnerability has been found by High-Tech Brdge SA and they qualified it as a low risk vulnerability.
Please download version 1.0.30 to fix these vulnerabilities. Download