AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2004-1870

HIGH · CVSS 7.5 EPSS 1.16%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2004-03-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2004-1870
Severity
HIGH
CVSS
7.5
EPSS
1.16%

Original NVD Description

Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.