PhotoPost PHP "index.php" SQL Injection Issue

Monday, August 2, 2010


PhotoPost PHP is a web-based photo gallery. The application is exposed to an SQL injection issue because it fails to sufficiently sanitize user-supplied data to the "cat" parameter of the "photopost/index.php" script before using it in an SQL query. PhotoPost PHP version 4.0 through 4.6 are affected.

Ref: http://www.securityfocus.com/bid/41916

10.31.61 - CVE: Not Available
Platform: Web Application - SQL Injection

0 comments:

Most Recent Post

MORE ON ARCHIVE
Widget by Mad Tomato

Help Me Expose This Article in Bulk!

Bookmark & Share

- OR -

SELECT YOUR PREFERRED ONE:

Bookmark and Share