Description
CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.
Problem types
Files or Directories Accessible to External Parties
Product status
Credits
David Tavarez
References
www.exploit-db.com/exploits/46094 (ExploitDB-46094)
davidtavarez.github.io/ (Official Product Homepage)
forum.codefuture.co.uk/showthread.php?tid=73141 (Product Reference)
www.vulncheck.com/...ing-script-unauthorized-database-access (VulnCheck Advisory: CF Image Hosting Script 1.6.5 Unauthorized Database Access)