Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension such as .gif.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
All Enthusiast PhotoPost PHP Pro多个远程漏洞
Vulnerability Description
PhotoPost PHP 5.0 RC3未完全验证上载文件是否为一图像文件,远程攻击者可以通过上载带有图像文件扩展名如.gif的非图像文件来注入任意Javascript。
CVSS Information
N/A
Vulnerability Type
N/A