CVE-2005-0778 Information
Feb 14, 2021
cve
Description
PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension such as .gif.
Reference
http://marc.info/?l=bugtraq&m=111065868402859&w=2 http://secunia.com/advisories/14576 http://www.securityfocus.com/bid/12779 https://exchange.xforce.ibmcloud.com/vulnerabilities/19679
Share on: