Filtered by vendor Photopost Subscriptions
Total 22 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2005-0928 1 Photopost 1 Photopost Php Pro 2025-04-03 N/A
Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) password, (3) ppuser, (4) sort, or (5) si parameters to showgallery.php, the (6) ppuser, (7) sort, or (8) si parameters to showmembers.php, or (9) the photo parameter to slideshow.php.
CVE-2005-0272 1 Photopost 1 Reviewpost Php Pro 2025-04-03 N/A
ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended restrictions.