Vulnerabilities > CVE-2005-0928 - Unspecified vulnerability in Photopost PHP PRO 5.02
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
NONE Integrity impact
PARTIAL Availability impact
NONE Summary
Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) password, (3) ppuser, (4) sort, or (5) si parameters to showgallery.php, the (6) ppuser, (7) sort, or (8) si parameters to showmembers.php, or (9) the photo parameter to slideshow.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description PhotoPost Pro 5.1 showgallery.php Multiple Parameter XSS. CVE-2005-0928. Webapps exploit for php platform id EDB-ID:25308 last seen 2016-02-03 modified 2005-03-28 published 2005-03-28 reporter Diabolic Crab source https://www.exploit-db.com/download/25308/ title PhotoPost Pro 5.1 showgallery.php Multiple Parameter XSS description PhotoPost Pro 5.1 showmembers.php Multiple Parameter XSS. CVE-2005-0928. Webapps exploit for php platform id EDB-ID:25309 last seen 2016-02-03 modified 2005-03-28 published 2005-03-28 reporter Diabolic Crab source https://www.exploit-db.com/download/25309/ title PhotoPost Pro 5.1 showmembers.php Multiple Parameter XSS description PhotoPost Pro 5.1 slideshow.php photo Parameter XSS. CVE-2005-0928. Webapps exploit for php platform id EDB-ID:25310 last seen 2016-02-03 modified 2005-03-28 published 2005-03-28 reporter Diabolic Crab source https://www.exploit-db.com/download/25310/ title PhotoPost Pro 5.1 slideshow.php photo Parameter XSS
Nessus
NASL family | CGI abuses |
NASL id | PHOTOPOST_MULTIPLE_INPUT_VULNS.NASL |
description | The version of PhotoPost PHP installed on the remote host is prone to multiple input validation vulnerabilities: o Multiple SQL Injection Vulnerabilities The application fails to properly sanitize user-input via the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 17649 |
published | 2005-03-30 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/17649 |
title | PhotoPost < 5.1 Multiple Input Validation Vulnerabilities |
code |
|