CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 12 Apr 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter. | |
| Title | CF Image Hosting Script 1.6.5 Unauthorized Database Access | |
| First Time appeared |
Scripteen
Scripteen free Image Hosting Script |
|
| Weaknesses | CWE-552 | |
| CPEs | cpe:2.3:a:scripteen:free_image_hosting_script:1.6.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Scripteen
Scripteen free Image Hosting Script |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-12T12:28:54.207Z
Reserved: 2026-04-12T12:14:33.041Z
Link: CVE-2019-25709
No data.
Status : Received
Published: 2026-04-12T13:16:33.950
Modified: 2026-04-12T13:16:33.950
Link: CVE-2019-25709
No data.
OpenCVE Enrichment
No data.
Weaknesses