Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and leverage them to gain administrator privileges, via the (1) category or (2) archivedate parameter.
References
Configurations
History
21 Nov 2024, 00:12
Type | Values Removed | Values Added |
---|---|---|
References | () http://retrogod.altervista.org/pixelpost_15rc12_xpl.html - Exploit | |
References | () http://securityreason.com/securityalert/1061 - | |
References | () http://securitytracker.com/id?1016217 - Exploit | |
References | () http://www.securityfocus.com/archive/1/435856/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/18276 - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/26922 - |
Information
Published : 2006-06-07 10:02
Updated : 2024-11-21 00:12
NVD link : CVE-2006-2889
Mitre link : CVE-2006-2889
CVE.ORG link : CVE-2006-2889
JSON object : View
Products Affected
pixelpost
- pixelpost
CWE