Vulnerabilities (CVE)

Filtered by vendor Photopost Subscribe
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-0778 1 Photopost 1 Photopost Php Pro 2025-04-03 5.0 MEDIUM N/A
PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension such as .gif.
CVE-2005-0273 1 Photopost 1 Photopost Php Pro 2025-04-03 7.5 HIGH N/A
Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.