approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.
References
Link | Resource |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2012-02/0180.html | Exploit |
http://www.exploit-db.com/exploits/18544 | Exploit |
Configurations
Information
Published : 2012-09-15 10:55
Updated : 2012-09-17 21:00
NVD link : CVE-2012-4926
Mitre link : CVE-2012-4926
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
imgpals
- img_pals_photo_host