CVE-2012-4926
Img Pals Photo Host 1.0 - RCE
Title source: llmDescription
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via the u parameter in an (1) app0 (disable) or (2) app1 (enable) action.
Exploits (1)
Scores
EPSS
0.0471
EPSS Percentile
89.2%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
imgpals/img_pals_photo_host
Timeline
Published
Sep 15, 2012
Tracked Since
Feb 18, 2026