Vendorsimgpalsimg_pals_photo_host1.0
Vulnerabilities

imgpals Img Pals Photo Host 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2012-4925
Multiple SQL injection vulnerabilities in approve.php in Img Pals Photo Host 1.0 allow remote attackers to execute arbitrary SQL commands via the u parameter in a (1) app0 or (2) app1 action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Published 2012-09-15 · Modified
7.51 PoCEPSS 0.012
CVE-2012-4926
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.
Published 2012-09-15 · Modified
6.41 PoCEPSS 0.019