CVE Vulnerabilities

CVE-2004-0250

Published: Nov 23, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.

Affected Software

Name Vendor Start Version End Version
Photopost_php_pro Photopost 3.1 (including) 3.1 (including)
Photopost_php_pro Photopost 3.2 (including) 3.2 (including)
Photopost_php_pro Photopost 3.3 (including) 3.3 (including)
Photopost_php_pro Photopost 4.0 (including) 4.0 (including)
Photopost_php_pro Photopost 4.1 (including) 4.1 (including)
Photopost_php_pro Photopost 4.6 (including) 4.6 (including)

References