CVE-2012-5891

DAlbum < 1.44 - Cross-Site Request Forgery in User Management

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-5891. PoCs published by Ahmed Elhady Mohamed.

AI-analyzed exploit summary This exploit demonstrates CSRF vulnerabilities in dalbum 144 build 174 and earlier, allowing an attacker to add, delete, or change user passwords via crafted HTML forms. The PoC includes three separate HTML forms targeting different actions (add user, change password, delete user).

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in photo/pass.php in DAlbum 1.44 build 174 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an add action, (2) change user passwords via a change action, or (3) delete a user via a delete action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ahmed Elhady Mohamed · textwebappsphp
https://www.exploit-db.com/exploits/18685

This exploit demonstrates CSRF vulnerabilities in dalbum 144 build 174 and earlier, allowing an attacker to add, delete, or change user passwords via crafted HTML forms. The PoC includes three separate HTML forms targeting different actions (add user, change password, delete user).

Classification
Working Poc 100%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: dalbum 144 build 174 and earlier
No auth needed
Prerequisites: Victim must visit a malicious webpage while authenticated to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/80745
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18685

Scores

EPSS 0.0107
EPSS Percentile 60.5%

Details

CWE
CWE-352
Status published
Products (18)
dalbum/dalbum 1.03
dalbum/dalbum 1.3
dalbum/dalbum 1.04
dalbum/dalbum 1.05
dalbum/dalbum 1.06
dalbum/dalbum 1.07
dalbum/dalbum 1.08
dalbum/dalbum 1.09
dalbum/dalbum 1.10
dalbum/dalbum 1.20
... and 8 more
Published Nov 17, 2012
Tracked Since Feb 18, 2026