PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension such as .gif.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Photopost_php_pro | Photopost | 5.0_rc3 (including) | 5.0_rc3 (including) |