Unrated severityNVD Advisory· Published Mar 29, 2004· Updated Jun 16, 2026
CVE-2004-1870
CVE-2004-1870
Description
Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7cpe:2.3:a:photopost:photopost_php_pro:3.1:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:photopost:photopost_php_pro:3.1:*:*:*:*:*:*:*
- cpe:2.3:a:photopost:photopost_php_pro:3.2:*:*:*:*:*:*:*
- cpe:2.3:a:photopost:photopost_php_pro:3.3:*:*:*:*:*:*:*
- cpe:2.3:a:photopost:photopost_php_pro:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:photopost:photopost_php_pro:4.1:*:*:*:*:*:*:*
- cpe:2.3:a:photopost:photopost_php_pro:4.6:*:*:*:*:*:*:*
- cpe:2.3:a:photopost:photopost_php_pro:4.8.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- secunia.com/advisories/11241nvdVendor Advisory
- securitytracker.com/idnvdVendor Advisory
- www.securityfocus.com/bid/9994nvdVendor Advisory
- marc.infonvd
- exchange.xforce.ibmcloud.com/vulnerabilities/15642nvd
News mentions
0No linked articles in our index yet.