Executive brief
CF Image Hosting Script is a web application used to host and manage image galleries. A security flaw allows anyone on the internet to download the application's internal database without a password. An attacker can use the information found in this database to delete all images hosted on the platform, leading to a total loss of data and service disruption.
Technical details
The vulnerability is caused by improper access control (CWE-552) on the 'imgdb.db' file located in the '/upload/data/' directory. This file contains base64-encoded, serialized PHP data representing the application's database. An unauthenticated remote attacker can download this file, decode it, and extract 'delete IDs' stored in plaintext. By passing these IDs to the 'd' parameter on the application's root URL, the attacker can programmatically delete every image in the system. No authentication or user interaction is required for exploitation.
Affected products
- CodeFuture CF Image Hosting Script 1.6.5
Timeline
- 2019-01-08: disclosed: Exploit code published on Exploit-DB
- 2026-04-12: advisory: CVE formally published/assigned via VulnCheck