6.5
CVSSv2

CVE-2011-1100

Published: 25/02/2011 Updated: 17/08/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) findfid, (2) id, (3) selectfcat, (4) selectfmon, or (5) selectftag parameter in an images action.

Vulnerable Product Search on Vulmon Subscribe to Product

pixelpost pixelpost 1.7.3

Exploits

-------------------------------------------------------------------- Pixelpost 173 Multiple POST Variables SQL Injection Vulnerability Vendor: Pixelpostorg Product web page: wwwpixelpostorg Affected version: 173 Summary: Pixelpost is an open-source, standards-compliant, multi-lingual, fully extensible photoblog application for the ...