vendor:
ImgPals Photo Host
by:
Corrado Liotta Aka CorryL
5.5
CVSS
MEDIUM
Admin Account Disactivation
287
CWE
Product Name: ImgPals Photo Host
Affected Version From: 1.0 STABLE
Affected Version To: 1.0 STABLE
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows, Linux, Unix
ImgPals Photo Host Version 1.0 STABLE
A attacker can remotely disable the account from administrator not allowing the same to be able to access the site
Mitigation:
Update the code to validate user input and prevent SQL injection attacks