Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w466-q2rw-4mm2

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.

approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.

EPSS

Процентиль: 85%
0.02626
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 13 лет назад

approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.

EPSS

Процентиль: 85%
0.02626
Низкий

Дефекты

CWE-287