Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9xm-p6vp-463x

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.

Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.

EPSS

Процентиль: 78%
0.0114
Низкий

Связанные уязвимости

nvd
больше 19 лет назад

Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.

EPSS

Процентиль: 78%
0.0114
Низкий