4.3
CVSSv2

CVE-2004-1871

Published: 29/03/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) ppuser, (2) password, (3) stype, (4) perpage, (5) sort, (6) page, (7) si, or (8) cat parameters to showmembers.php, or the (9) photo name, (10) photo description, (11) album name, or (12) album description fields.

Vulnerable Product Search on Vulmon Subscribe to Product

photopost photopost php pro 3.1

photopost photopost php pro 3.2

photopost photopost php pro 3.3

photopost photopost php pro 4.0

photopost photopost php pro 4.8.1

photopost photopost php pro 4.1

photopost photopost php pro 4.6

Exploits

PhotoPost Multiple Vulnerabilities Vendor: All Enthusiast, Inc Product: PhotoPost Version: <= 46 Website: wwwphotopostcom/ BID: 9994 CVE: CVE-2004-1870 CVE-2004-1871 OSVDB: 10261 10262 10263 10264 10265 10266 10267 4771 SECUNIA: 11241 Description: PhotoPost was designed to help you give your users exactly what they want Your us ...