CVE-2004-0250

SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:photopost:photopost_php_pro:3.1:*:*:*:*:*:*:*
cpe:2.3:a:photopost:photopost_php_pro:3.2:*:*:*:*:*:*:*
cpe:2.3:a:photopost:photopost_php_pro:3.3:*:*:*:*:*:*:*
cpe:2.3:a:photopost:photopost_php_pro:4.0:*:*:*:*:*:*:*
cpe:2.3:a:photopost:photopost_php_pro:4.1:*:*:*:*:*:*:*
cpe:2.3:a:photopost:photopost_php_pro:4.6:*:*:*:*:*:*:*

History

20 Nov 2024, 23:48

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=107593114909696&w=2 - () http://marc.info/?l=bugtraq&m=107593114909696&w=2 -
References () http://www.securityfocus.com/bid/9557 - Exploit, Vendor Advisory () http://www.securityfocus.com/bid/9557 - Exploit, Vendor Advisory
References () http://www.zone-h.org/en/advisories/read/id=3864/ - () http://www.zone-h.org/en/advisories/read/id=3864/ -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/15008 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/15008 -

Information

Published : 2004-11-23 05:00

Updated : 2024-11-20 23:48


NVD link : CVE-2004-0250

Mitre link : CVE-2004-0250

CVE.ORG link : CVE-2004-0250


JSON object : View

Products Affected

photopost

  • photopost_php_pro