peter bassill · operator
$ cve CVE-2004-0239 JSON

CVE-2004-0239 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 3.3% (pctl 88)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS3.31% — more likely to be exploited than 88% of all CVEs
On CISA KEVno
Public exploityes
Published2004-11-23
Last modified2026-06-16

Affected (1)

VendorProduct
photopostphotopost php pro

Public exploits

SourceTitleDate
exploit-dbPhotoPost PHP 4.6.5 - 'ecard.php' SQL Injection2010-07-23

References

→ the Explorer  ·  watch your stack  ·  NVD