CVE-2005-0775 Information

Description

The reportpost action in misc.php for PhotoPost PHP 5.0 RC3 does not limit the logging data that is sent to the administrator which allows remote attackers to send large amounts of email to the administrator.

Reference

http://marc.info/?l=bugtraq&m=111065868402859&w=2 http://secunia.com/advisories/14576 http://www.securityfocus.com/bid/12779 https://exchange.xforce.ibmcloud.com/vulnerabilities/19676

Share on: