Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) findfid, (2) id, (3) selectfcat, (4) selectfmon, or (5) selectftag parameter in an images action.
References
Configurations
History
21 Nov 2024, 01:25
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.exploit-db.com/exploits/16160 - Exploit | |
References | () http://www.zeroscience.mk/en/vulnerabilities/ZSL-2011-4992.php - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/65474 - |
Information
Published : 2011-02-25 17:00
Updated : 2024-11-21 01:25
NVD link : CVE-2011-1100
Mitre link : CVE-2011-1100
CVE.ORG link : CVE-2011-1100
JSON object : View
Products Affected
pixelpost
- pixelpost
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')