7.5
CVSSv2

CVE-2011-4710

Published: 08/12/2011 Updated: 29/03/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Pixie CMS 1.01 up to and including 1.04 allow remote malicious users to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lucidcrew pixie 1.04

lucidcrew pixie 1.03

getpixie pixie 1.01a

getpixie pixie 1.01

lucidcrew pixie 1.02

Exploits

Exploit Title: Pixie CMS 101 - 104 "pixie_user" Blind SQL Injection Google Dork: None Date: 11/14/2011 Author: Piranha, piranha[at]torontomailcom Software Link: wwwgetpixiecouk/ Version: 101 - 104 Tested on: Windows XP SP3, Pixie versions: 101 - 104 CVE : None Example request: GET localhost:8080/pixie_v104/?pixie_user=x',l ...