Filtered by vendor Photopost Subscriptions
Total 22 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2004-1871 1 Photopost 1 Photopost Php Pro 2025-04-03 N/A
Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ppuser, (2) password, (3) stype, (4) perpage, (5) sort, (6) page, (7) si, or (8) cat parameters to showmembers.php, or the (9) photo name, (10) photo description, (11) album name, or (12) album description fields.
CVE-2005-0271 1 Photopost 1 Reviewpost Php Pro 2025-04-03 N/A
Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) product parameter to addfav.php.