VulnerabilityModified
CVE-2005-0778
PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension such as .gif.
MEDIUM 5.0EPSS 1.39%
Does this matter?
Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.
Description
PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension such as .gif.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Affected
- photopost/photopost php pro
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=111065868402859&w=2
- http://secunia.com/advisories/14576
- http://www.securityfocus.com/bid/12779
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19679
- http://marc.info/?l=bugtraq&m=111065868402859&w=2
- http://secunia.com/advisories/14576
- http://www.securityfocus.com/bid/12779
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19679
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.