Back

CVE-2004-0250

SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.

Published: Nov 23, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
photopost photopost_php_pro 3.1
photopost photopost_php_pro 3.2
photopost photopost_php_pro 3.3
photopost photopost_php_pro 4.0
photopost photopost_php_pro 4.1
photopost photopost_php_pro 4.6

GitHub Security Advisory GHSA-rfg7-c2cq-64vm

SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 3.19%

Top 13% most likely to be exploited

Threat Score 41 / 100

Data Sources

NVD EPSS GitHub