CVE-2005-0929 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.6% (pctl 85)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo parameter to showphoto.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.61% — more likely to be exploited than 85% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-05-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| photopost | photopost php pro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PhotoPost PHP 4.6.5 - 'ecard.php' SQL Injection | 2010-07-23 |
| exploit-db | PhotoPost Pro 5.1 - 'showmembers.php?sl' SQL Injection | 2005-03-28 |
| exploit-db | PhotoPost Pro 5.1 - 'showphoto.php?photo' SQL Injection | 2005-03-28 |
References
- http://marc.info/?l=bugtraq&m=111205342909640&w=2
- http://marc.info/?l=bugtraq&m=111213719017716&w=2
- http://secunia.com/advisories/14742
- http://securitytracker.com/id?1013581
- http://www.osvdb.org/15099
- http://www.osvdb.org/15100
- http://marc.info/?l=bugtraq&m=111205342909640&w=2
- http://marc.info/?l=bugtraq&m=111213719017716&w=2
- http://secunia.com/advisories/14742
- http://securitytracker.com/id?1013581
- http://www.osvdb.org/15099
- http://www.osvdb.org/15100
→ the Explorer · watch your stack · NVD