Skip to main content

Vendor/product archive

photopost / photopost_php_pro CVEs

Beta · best-effort

17 CVEs tagged to photopost / photopost_php_pro2 Critical, 8 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2006-4990

Published Sep 26, 2006

Multiple PHP remote file inclusion vulnerabilities in PhotoPost allow remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter in (1) addfav.php, (2) adm-…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-4828

Published Sep 15, 2006

PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2737

Published Aug 30, 2005

Cross-site scripting (XSS) vulnerability in PhotoPost PHP Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1629

Published May 17, 2005

SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0273

Published May 2, 2005

Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0775

Published May 2, 2005

The reportpost action in misc.php for PhotoPost PHP 5.0 RC3 does not limit the logging data that is sent to the administrator, which allows remote attackers to send large amounts…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0776

Published May 2, 2005

adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow remote attackers to manipulate other users'…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0777

Published May 2, 2005

Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP 5.0 RC3 allow remote attackers to inject arbitrary web script or HTML via (1) the check_tags function or (2) t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0778

Published May 2, 2005

PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0928

Published May 2, 2005

Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) password, (3) ppuse…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0929

Published May 2, 2005

SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo para…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0774

Published Mar 10, 2005

SQL injection vulnerability in member.php and possibly other scripts in PhotoPost PHP 5.0 RC3 allows remote attackers to execute arbitrary SQL commands via the uid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-0274

Published Jan 3, 2005

Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0239

Published Nov 23, 2004

SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0250

Published Nov 23, 2004

SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat paramet…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1870

Published Mar 29, 2004

Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1871

Published Mar 29, 2004

Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ppuser, (2) pa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1