vendor:
Photopost PHP Pro
by:
Unknown
7.5
CVSS
HIGH
SQL Injection, Cross-Site Scripting, HTML Injection
Unknown
CWE
Product Name: Photopost PHP Pro
Affected Version From: 4.6.2000
Affected Version To: 4.8.2001
Patch Exists: YES
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
Multiple SQL Injection, Cross-Site Scripting, and HTML Injection Vulnerabilities in Photopost PHP Pro
The application is prone to multiple vulnerabilities including SQL injection, cross-site scripting, and HTML injection. These vulnerabilities may allow an attacker to execute arbitrary HTML or script code in a user's browser and/or influence SQL query logic to disclose sensitive information and carry out other attacks.
Mitigation:
It is recommended to update to a secure version of Photopost PHP Pro that addresses these vulnerabilities. Additionally, input validation and output encoding should be implemented to prevent SQL injection, cross-site scripting, and HTML injection attacks.