CRITICAL
CF Image Hosting Script 1.6.5 Unauthorized Database Access
Published Apr 12, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.61%
Description
CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.
Affected products
-
- Version 1.6.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Davidtavarez | CF Image Hosting Script | n/a |
|
- 1.6.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://forum.codefuture.co.uk/showthread.php?tid=73141 productBroken Link
- https://davidtavarez.github.io/ productThird Party Advisory
- https://www.exploit-db.com/exploits/46094 exploitVDB Entry
- https://www.vulncheck.com/advisories/cf-image-hosting-script-unauthorized-database-access third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://forum.codefuture.co.uk/showthread.php?tid=73141 | productBroken Link | |
| https://davidtavarez.github.io/ | productThird Party Advisory | |
| https://www.exploit-db.com/exploits/46094 | exploitVDB Entry | |
| https://www.vulncheck.com/advisories/cf-image-hosting-script-unauthorized-database-access | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 12, 2026
Updated Apr 15, 2026
Reserved Apr 12, 2026
Link CVE-2019-25709
CISA Vulnrichment
Updated Apr 15, 2026