CVE-2012-4925

Img Pals Photo Host 1.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-4925. PoCs published by CorryL.

AI-analyzed exploit summary The exploit demonstrates an authentication bypass vulnerability in ImgPals Photo Host 1.0 STABLE, allowing an attacker to disable the administrator account by sending a crafted HTTP request to 'approve.php'. The PoC uses cURL to manipulate the 'approved' field in the database via SQL injection.

Description

Multiple SQL injection vulnerabilities in approve.php in Img Pals Photo Host 1.0 allow remote attackers to execute arbitrary SQL commands via the u parameter in a (1) app0 or (2) app1 action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WORKING POC
by CorryL · textwebappsphp
https://www.exploit-db.com/exploits/18544

The exploit demonstrates an authentication bypass vulnerability in ImgPals Photo Host 1.0 STABLE, allowing an attacker to disable the administrator account by sending a crafted HTTP request to 'approve.php'. The PoC uses cURL to manipulate the 'approved' field in the database via SQL injection.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: ImgPals Photo Host 1.0 STABLE
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48182
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52195
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18544
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-02/0180.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/73526
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/79670

Scores

EPSS 0.0124
EPSS Percentile 65.2%

Details

CWE
CWE-89
Status published
Products (1)
imgpals/img_pals_photo_host 1.0
Published Sep 15, 2012
Tracked Since Feb 18, 2026