PoC Index

CVE-2005-0928

MEDIUM 4.3EPSS 4.0%

Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) password, (3) ppuser, (4) sort, or (5) si parameters to showgallery.php, the (6) ppuser, (7) sort, or (8) si parameters to showmembers.php, or (9) the photo parameter to slideshow.php.

CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
3.99% chance of exploitation in the next 30 days, 90th percentile
Published
2005-03-29
Updated
2024-08-07

ExploitDB entries (3)

References

Related