7.5
CVSSv2

CVE-2006-4828

Published: 15/09/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 up to and including 4.6 allows remote malicious users to execute arbitrary PHP code via a URL in the PP_PATH parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

photopost photopost php pro 4.0

photopost photopost php pro 4.1

photopost photopost php pro 4.2

photopost photopost php pro 4.3

photopost photopost php pro 4.6

photopost photopost php pro 4.4

photopost photopost php pro 4.5

Exploits

#==================================================================== #PhotoPost => 46 (PP_PATH) Remote File Inclusion Exploit #==================================================================== # #Critical Level : Dangerous # #By Saudi Hackrz # #wwwpopphotocom/ # #================================================================= # # ...