{"api_version":"1","generated_at":"2026-07-23T12:42:34+00:00","cve":"CVE-2004-1870","urls":{"html":"https://cve.report/CVE-2004-1870","api":"https://cve.report/api/cve/CVE-2004-1870.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1870","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1870"},"summary":{"title":"CVE-2004-1870","description":"Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-03-29 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/9994","name":"http://www.securityfocus.com/bid/9994","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"All Enthusiast Photopost PHP Pro Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=108057790723123&w=2","name":"http://marc.info/?l=bugtraq&m=108057790723123&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'PhotoPost PHP Pro Multiple Vulnerabilities' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1009571","name":"http://securitytracker.com/id?1009571","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SecurityTracker.com Archives - PhotoPost PHP Pro Has Multiple Input Validation Holes That Let Remote Users Inject SQL Commands and Conduct Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15642","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15642","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/11241","name":"http://secunia.com/advisories/11241","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - PhotoPost Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1870","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1870","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1870","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photopost","cpe5":"photopost_php_pro","cpe6":"3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1870","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photopost","cpe5":"photopost_php_pro","cpe6":"3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1870","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photopost","cpe5":"photopost_php_pro","cpe6":"3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1870","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photopost","cpe5":"photopost_php_pro","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1870","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photopost","cpe5":"photopost_php_pro","cpe6":"4.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1870","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photopost","cpe5":"photopost_php_pro","cpe6":"4.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1870","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photopost","cpe5":"photopost_php_pro","cpe6":"4.8.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:07:49.031Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"9994","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/9994"},{"name":"20040328 PhotoPost PHP Pro Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=108057790723123&w=2"},{"name":"photopost-php-sql-injection(15642)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15642"},{"name":"1009571","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1009571"},{"name":"11241","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/11241"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-03-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"9994","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/9994"},{"name":"20040328 PhotoPost PHP Pro Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=108057790723123&w=2"},{"name":"photopost-php-sql-injection(15642)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15642"},{"name":"1009571","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1009571"},{"name":"11241","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/11241"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1870","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"9994","refsource":"BID","url":"http://www.securityfocus.com/bid/9994"},{"name":"20040328 PhotoPost PHP Pro Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=108057790723123&w=2"},{"name":"photopost-php-sql-injection(15642)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/15642"},{"name":"1009571","refsource":"SECTRACK","url":"http://securitytracker.com/id?1009571"},{"name":"11241","refsource":"SECUNIA","url":"http://secunia.com/advisories/11241"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1870","datePublished":"2005-05-10T04:00:00.000Z","dateReserved":"2005-05-04T00:00:00.000Z","dateUpdated":"2024-08-08T01:07:49.031Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-03-29 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:photopost:photopost_php_pro:3.1:*:*:*:*:*:*:*","matchCriteriaId":"C2C8CE03-944A-480E-9349-9143A74ADCBB"},{"vulnerable":true,"criteria":"cpe:2.3:a:photopost:photopost_php_pro:3.2:*:*:*:*:*:*:*","matchCriteriaId":"762D922E-387C-41D6-BA4B-9D97692B7570"},{"vulnerable":true,"criteria":"cpe:2.3:a:photopost:photopost_php_pro:3.3:*:*:*:*:*:*:*","matchCriteriaId":"8D07B06C-3872-4D39-95FA-C0FAEBD9C2DD"},{"vulnerable":true,"criteria":"cpe:2.3:a:photopost:photopost_php_pro:4.0:*:*:*:*:*:*:*","matchCriteriaId":"C36E11FE-5E1F-4BF9-A223-64B74984C5DE"},{"vulnerable":true,"criteria":"cpe:2.3:a:photopost:photopost_php_pro:4.1:*:*:*:*:*:*:*","matchCriteriaId":"5D19ECFF-EAE7-4FCB-BE21-B0C08FF65AAC"},{"vulnerable":true,"criteria":"cpe:2.3:a:photopost:photopost_php_pro:4.6:*:*:*:*:*:*:*","matchCriteriaId":"8F04E77C-C9ED-4CAE-964C-6AB395BFEBE4"},{"vulnerable":true,"criteria":"cpe:2.3:a:photopost:photopost_php_pro:4.8.1:*:*:*:*:*:*:*","matchCriteriaId":"E8DEC786-BC61-44F7-8B93-3ECDA07C0772"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1870","Ordinal":"1","Title":"CVE-2004-1870","CVE":"CVE-2004-1870","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1870","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo parameter to comments.php, (3) credit parameter to comments.php, (4) cat parameter to index.php, (5) ppuser parameter to showgallery.php, (6) cat parameter to showgallery.php, (7) cat parameter to uploadphoto.php, (8) albumid parameter to useralbums.php, or (9) albumid parameter to useralbums.php.","Type":"Description","Title":"CVE-2004-1870"},{"CveYear":"2004","CveId":"1870","Ordinal":"2","NoteData":"2005-05-10","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1870","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}