peter bassill · operator
$ cve CVE-2005-0929 JSON

CVE-2005-0929 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo parameter to showphoto.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.61% — more likely to be exploited than 85% of all CVEs
On CISA KEVno
Public exploityes
Published2005-05-02
Last modified2026-06-16

Affected (1)

VendorProduct
photopostphotopost php pro

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD