Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
pixie vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2011-4710
Multiple SQL injection vulnerabilities in Pixie CMS 1.01 up to and including 1.04 allow remote malicious users to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI.
Lucidcrew Pixie 1.04
Lucidcrew Pixie 1.03
Getpixie Pixie 1.01a
Getpixie Pixie 1.01
Lucidcrew Pixie 1.02
1 EDB exploit
7.5
CVSSv2
CVE-2019-10766
Pixie versions 1.0.x prior to 1.0.3, and 2.0.x prior to 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.
Pixie Project Pixie
7.5
CVSSv2
CVE-2017-12905
Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote malicious users to disclose information or execute arbitrary code via the url parameter to Launderer.php.
Vebto Pixie - Image Editor 1.4
Vebto Pixie - Image Editor 1.7
4.3
CVSSv2
CVE-2017-7359
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.
Lucidcrew Pixie 1.04
4.3
CVSSv2
CVE-2017-7361
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.
Lucidcrew Pixie 1.04
7.5
CVSSv2
CVE-2017-7402
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.
Lucidcrew Pixie 1.04
1 EDB exploit
4.3
CVSSv2
CVE-2017-7363
Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.
Lucidcrew Pixie 1.04
4.3
CVSSv2
CVE-2017-7360
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.
Lucidcrew Pixie 1.04
4.3
CVSSv2
CVE-2017-7362
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.
Lucidcrew Pixie 1.04
5
CVSSv2
CVE-2011-3793
Pixie 1.04 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files.
Lucidcrew Pixie 1.04
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »