PT-2012-5660 · Img Pals · Img Pals Photo Host

Corrado Liotta

+1

·

Published

2012-09-15

·

Updated

2017-08-29

·

CVE-2012-4925

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Img Pals Photo Host version 1.0
Description The issue concerns SQL injection vulnerabilities in the approve.php file. Remote attackers can execute arbitrary SQL commands via the u parameter in certain actions, specifically in (1) app0 or (2) app1 actions.
Recommendations For Img Pals Photo Host version 1.0, consider restricting access to the approve.php file until a fix is available, and avoid using the u parameter in app0 or app1 actions to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4925

Affected Products

Img Pals Photo Host