Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Photopost_php_pro | Photopost | * | 4.85 (including) |