Back
CVE-2004-0250
SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.
Published: Nov 23, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (6)
| Vendor | Product | Version |
|---|---|---|
| photopost | photopost_php_pro | 3.1 |
| photopost | photopost_php_pro | 3.2 |
| photopost | photopost_php_pro | 3.3 |
| photopost | photopost_php_pro | 4.0 |
| photopost | photopost_php_pro | 4.1 |
| photopost | photopost_php_pro | 4.6 |
GitHub Security Advisory GHSA-rfg7-c2cq-64vm
SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain...
References (8)
- http://marc.info/?l=bugtraq&m=107593114909696&w=2
- http://www.securityfocus.com/bid/9557 Exploit, Vendor Advisory
- http://www.zone-h.org/en/advisories/read/id=3864/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15008
- http://marc.info/?l=bugtraq&m=107593114909696&w=2
- http://www.securityfocus.com/bid/9557 Exploit, Vendor Advisory
- http://www.zone-h.org/en/advisories/read/id=3864/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15008
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
3.19%
Top 13% most likely to be exploited
Threat Score
41 / 100
Data Sources
NVD
EPSS
GitHub