6.4
CVSSv2

CVE-2006-5086

Published: 29/09/2006 Updated: 17/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Blog Pixel Motion 2.1.1 allows remote malicious users to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.

Vulnerable Product Search on Vulmon Subscribe to Product

pixel motion pixel motion blog 2.1.1

Exploits

#!/usr/bin/perl # # Affectedscr: Blog Pixel Motion V211 # PocID: 12060927 # Type: PHP Code Execution (stripslashes), SQL Injection (urldecode) # Risklevel: High # VendorStatus: Unpatched # Srcdownload: wwwpixelmotionorg/zip/blog21zip # Poclink: acid-rootnewfr/poc/12060927txt # Credits: DarkFig ...