CVE-2005-0778

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/05/2005
Last modified:
03/04/2025

Description

PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension such as .gif.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:photopost:photopost_php_pro:5.0_rc3:*:*:*:*:*:*:*