CVE-2004-1870

Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:photopost:photopost_php_pro:3.1:*:*:*:*:*:*:*
cpe:2.3:a:photopost:photopost_php_pro:3.2:*:*:*:*:*:*:*
cpe:2.3:a:photopost:photopost_php_pro:3.3:*:*:*:*:*:*:*
cpe:2.3:a:photopost:photopost_php_pro:4.0:*:*:*:*:*:*:*
cpe:2.3:a:photopost:photopost_php_pro:4.1:*:*:*:*:*:*:*
cpe:2.3:a:photopost:photopost_php_pro:4.6:*:*:*:*:*:*:*
cpe:2.3:a:photopost:photopost_php_pro:4.8.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2004-03-29 05:00

Updated : 2024-02-28 10:24


NVD link : CVE-2004-1870

Mitre link : CVE-2004-1870

CVE.ORG link : CVE-2004-1870


JSON object : View

Products Affected

photopost

  • photopost_php_pro