7.5
CVSSv2

CVE-2009-1066

Published: 26/03/2009 Updated: 14/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the referral function in admin/lib/lib_logs.php in Pixie CMS 1.01a allows remote malicious users to execute arbitrary SQL commands via the Referer HTTP header in a request.

Vulnerable Product Search on Vulmon Subscribe to Product

getpixie pixie cms 1.01a

Exploits

Pixie CMS Multiple Vulnerabilities Pixie is a "free, open source web application that will help you quickly create your own website Many people refer to this type of software as a 'content management system (cms)'" (wwwgetpixiecouk) Pixie is written in PHP with a MySQL database back end Pixie Blog XSS It is possible to trivially i ...