{
    "id": "CVE-2005-0929",
    "published": "2005-05-02 04:00:00",
    "last_modified": "2026-06-16 22:12:04",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
    "cwe": null,
    "description": "SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo parameter to showphoto.php.",
    "epss_score": "0.02614",
    "epss_percentile": "0.84986",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-09 18:17:05",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "photopost",
            "product": "photopost_php_pro"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "14453",
            "title": "PhotoPost PHP 4.6.5 - 'ecard.php' SQL Injection",
            "date": "2010-07-23",
            "url": "https://www.exploit-db.com/exploits/14453"
        },
        {
            "source": "exploit-db",
            "ref_id": "25311",
            "title": "PhotoPost Pro 5.1 - 'showmembers.php?sl' SQL Injection",
            "date": "2005-03-28",
            "url": "https://www.exploit-db.com/exploits/25311"
        },
        {
            "source": "exploit-db",
            "ref_id": "25312",
            "title": "PhotoPost Pro 5.1 - 'showphoto.php?photo' SQL Injection",
            "date": "2005-03-28",
            "url": "https://www.exploit-db.com/exploits/25312"
        }
    ],
    "refs_list": [
        "http://marc.info/?l=bugtraq&m=111205342909640&w=2",
        "http://marc.info/?l=bugtraq&m=111213719017716&w=2",
        "http://secunia.com/advisories/14742",
        "http://securitytracker.com/id?1013581",
        "http://www.osvdb.org/15099",
        "http://www.osvdb.org/15100",
        "http://marc.info/?l=bugtraq&m=111205342909640&w=2",
        "http://marc.info/?l=bugtraq&m=111213719017716&w=2",
        "http://secunia.com/advisories/14742",
        "http://securitytracker.com/id?1013581",
        "http://www.osvdb.org/15099",
        "http://www.osvdb.org/15100"
    ]
}