Vulnerability Description
adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow remote attackers to manipulate other users' photos.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Photopost | Photopost Php Pro | 5.0_rc3 |
References
- http://marc.info/?l=bugtraq&m=111065868402859&w=2
- http://secunia.com/advisories/14576
- http://www.securityfocus.com/bid/12779
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19677
- http://marc.info/?l=bugtraq&m=111065868402859&w=2
- http://secunia.com/advisories/14576
- http://www.securityfocus.com/bid/12779
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19677
FAQ
What is CVE-2005-0776?
CVE-2005-0776 is a vulnerability with a CVSS score of 5.0 (MEDIUM). adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow remote attackers to manipulate other users' photos.
How severe is CVE-2005-0776?
CVE-2005-0776 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-0776?
Check the references section above for vendor advisories and patch information. Affected products include: Photopost Photopost Php Pro.