vendor:
CF Image Hosting Script
by:
David Tavarez
7.5
CVSS
HIGH
Database Download
200
CWE
Product Name: CF Image Hosting Script
Affected Version From: 1.6.5
Affected Version To: 1.6.5
Patch Exists: NO
Related CWE: N/A
CPE: a:codefuture:cf_image_hosting_script:1.6.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Debian 9.6
2019
CF Image Hosting Script 1.6.5: Delete database
By default, the database can be downloaded by any user. After decoding the file the database should be unserialize. The DELETE ID is stored in Plain Text, this ID can be use to delete a picture.
Mitigation:
Ensure that the database is not accessible to unauthorized users.