PT-2012-5660 · Img Pals · Img Pals Photo Host

Corrado Liotta

+1

·

Publicado

2012-09-15

·

Atualizado

2017-08-29

·

CVE-2012-4925

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Img Pals Photo Host version 1.0
Description The issue concerns SQL injection vulnerabilities in the approve.php file. Remote attackers can execute arbitrary SQL commands via the u parameter in certain actions, specifically in (1) app0 or (2) app1 actions.
Recommendations For Img Pals Photo Host version 1.0, consider restricting access to the approve.php file until a fix is available, and avoid using the u parameter in app0 or app1 actions to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-4925

Produtos afetados

Img Pals Photo Host