Multiple cross-site request forgery (CSRF) vulnerabilities in photo/pass.php in DAlbum 1.44 build 174 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an add action, (2) change user passwords via a change action, or (3) delete a user via a delete action.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dalbum | Dalbum | * | 1.44 (including) |
Dalbum | Dalbum | 1.03 (including) | 1.03 (including) |
Dalbum | Dalbum | 1.3 (including) | 1.3 (including) |
Dalbum | Dalbum | 1.04 (including) | 1.04 (including) |
Dalbum | Dalbum | 1.05 (including) | 1.05 (including) |
Dalbum | Dalbum | 1.06 (including) | 1.06 (including) |
Dalbum | Dalbum | 1.07 (including) | 1.07 (including) |
Dalbum | Dalbum | 1.08 (including) | 1.08 (including) |
Dalbum | Dalbum | 1.09 (including) | 1.09 (including) |
Dalbum | Dalbum | 1.10 (including) | 1.10 (including) |
Dalbum | Dalbum | 1.20 (including) | 1.20 (including) |
Dalbum | Dalbum | 1.21 (including) | 1.21 (including) |
Dalbum | Dalbum | 1.22 (including) | 1.22 (including) |
Dalbum | Dalbum | 1.22-sp2 (including) | 1.22-sp2 (including) |
Dalbum | Dalbum | 1.22-sp3 (including) | 1.22-sp3 (including) |
Dalbum | Dalbum | 1.22-sp4 (including) | 1.22-sp4 (including) |
Dalbum | Dalbum | 1.22-sp5 (including) | 1.22-sp5 (including) |
Dalbum | Dalbum | 1.22-sp6 (including) | 1.22-sp6 (including) |
Dalbum | Dalbum | 1.22-sp7 (including) | 1.22-sp7 (including) |
Dalbum | Dalbum | 1.31 (including) | 1.31 (including) |
Dalbum | Dalbum | 1.32 (including) | 1.32 (including) |
Dalbum | Dalbum | 1.33 (including) | 1.33 (including) |
Dalbum | Dalbum | 1.34 (including) | 1.34 (including) |
Dalbum | Dalbum | 1.35 (including) | 1.35 (including) |