CVE-2004-1870
Last modified
CVE-2004-1870 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Photopost | Photopost Php Pro | 3.1 |
| Photopost | Photopost Php Pro | 3.2 |
| Photopost | Photopost Php Pro | 3.3 |
| Photopost | Photopost Php Pro | 4.0 |
| Photopost | Photopost Php Pro | 4.1 |
| Photopost | Photopost Php Pro | 4.6 |
| Photopost | Photopost Php Pro | 4.8.1 |
References
- http://secunia.com/advisories/11241Vendor Advisory
- http://securitytracker.com/id?1009571Vendor Advisory
- http://www.securityfocus.com/bid/9994Vendor Advisory
- http://secunia.com/advisories/11241Vendor Advisory
- http://securitytracker.com/id?1009571Vendor Advisory
- http://www.securityfocus.com/bid/9994Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-1870?
How severe is CVE-2004-1870?
How do I fix CVE-2004-1870?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-1864SQL injection vulnerability in Extreme Messageboard (XMB) 1.…
- CVE-2004-1865Cross-site scripting (XSS) vulnerability in the administrati…4.8
- CVE-2004-1866nstxd in Nstx 1.1 beta3 and earlier allows remote attackers …
- CVE-2004-1867Cross-site scripting (XSS) vulnerability in guest.cgi in Fre…
- CVE-2004-1868Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and…
- CVE-2004-1869Etherlords I 1.07 and earlier and Etherlords II 1.03 and ear…
- CVE-2004-1871Multiple cross-site scripting (XSS) vulnerabilities in Photo…
- CVE-2004-1872Cross-site scripting (XSS) vulnerability in WebCT Campus Edi…
- CVE-2004-1873SQL injection vulnerability in category.asp in A-CART Pro an…
- CVE-2004-1874Multiple cross-site scripting (XSS) vulnerabilities in (1) d…
- CVE-2004-1875Multiple cross-site scripting (XSS) vulnerabilities in cPane…
- CVE-2004-1876The "%f" feature in the VirusEvent directive in Clam AntiVir…
Are you affected by CVE-2004-1870?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
