CVE-2005-0928
PhotoPost PHP Pro 5.x - Cross-Site Scripting via Multiple Parameters
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2005-0928. PoCs published by Diabolic Crab.
AI-analyzed exploit summary The provided text describes multiple input validation vulnerabilities in PhotoPost Pro, including XSS and SQL injection flaws. It outlines affected scripts and parameters but does not include executable exploit code.
Description
Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) password, (3) ppuser, (4) sort, or (5) si parameters to showgallery.php, the (6) ppuser, (7) sort, or (8) si parameters to showmembers.php, or (9) the photo parameter to slideshow.php.
Exploits (3)
The provided text describes multiple input validation vulnerabilities in PhotoPost Pro, including XSS and SQL injection flaws. It outlines affected scripts and parameters but does not include executable exploit code.
The provided text describes multiple input validation vulnerabilities in PhotoPost Pro, including XSS and SQL injection flaws. It includes example URLs demonstrating XSS attacks but does not contain executable exploit code.
The provided text describes multiple input validation vulnerabilities in PhotoPost Pro, including XSS and SQL injection flaws. It includes example URLs demonstrating the vulnerabilities but does not contain executable exploit code.