Unrated severityNVD Advisory· Published Mar 29, 2004· Updated Apr 16, 2026
CVE-2004-1870
CVE-2004-1870
Description
Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.
Affected products
7cpe:2.3:a:photopost:photopost_php_pro:3.1:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:photopost:photopost_php_pro:3.1:*:*:*:*:*:*:*
- cpe:2.3:a:photopost:photopost_php_pro:3.2:*:*:*:*:*:*:*
- cpe:2.3:a:photopost:photopost_php_pro:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:photopost:photopost_php_pro:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:photopost:photopost_php_pro:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:photopost:photopost_php_pro:4.6:*:*:*:*:*:*:*
- cpe:2.3:a:photopost:photopost_php_pro:4.8.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- secunia.com/advisories/11241nvdVendor Advisory
- securitytracker.com/idnvdVendor Advisory
- www.securityfocus.com/bid/9994nvdVendor Advisory
- marc.infonvd
- exchange.xforce.ibmcloud.com/vulnerabilities/15642nvd
News mentions
0No linked articles in our index yet.