10
CVE-2004-0250
- EPSS 3.19%
- Veröffentlicht 23.11.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:05:15
- Erkennungen
SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat parameter in showcat.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Photopost ≫ Photopost Php Pro Version 3.1
Photopost ≫ Photopost Php Pro Version 3.2
Photopost ≫ Photopost Php Pro Version 3.3
Photopost ≫ Photopost Php Pro Version 4.0
Photopost ≫ Photopost Php Pro Version 4.1
Photopost ≫ Photopost Php Pro Version 4.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.19% | 0.864 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
http://www.securityfocus.com/bid/9557
https://exchange.xforce.ibmcloud.com/vulnerabilities/15008
http://marc.info/?l=bugtraq&m=107593114909696&w=2
http://www.zone-h.org/en/advisories/read/id=3864/