9
CVSSv2

CVE-2008-1866

Published: 17/04/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request.

Vulnerable Product Search on Vulmon Subscribe to Product

pixel motion pixel motion blog

Exploits

------------------------------------------------------------------------- -- JIKI Team [ JIKO + KIl1er ] --- ------------------------------------------------------------------------- # Author : jiko [jiki team] # email : jalikom@hotmailcom # Home : wwwno-backorg # Script : Blog PixelMotion # Bug : Database Backup Dump V ...