PT-2005-1956 · Unknown · Photopost Php Pro
James Bercegay
·
Publicado
2005-03-29
·
Atualizado
2016-10-18
·
CVE-2005-0929
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PhotoPost PHP Pro versions 5.x
Description
A SQL injection issue may allow remote attackers to execute arbitrary SQL commands. This can be achieved via the
sl parameter to "showmembers.php" or the photo parameter to "showphoto.php".Recommendations
For PhotoPost PHP Pro version 5.x, update to a version that includes a fix for this issue to prevent SQL injection attacks.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Photopost Php Pro