PoC Index

CVE-2006-1426

HIGH 7.5EPSS 1.9%

Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authentication via the (2) password parameter in admin/index.php.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.93% chance of exploitation in the next 30 days, 79th percentile
Published
2006-03-28
Updated
2024-08-07

ExploitDB entries (2)

References

Related