Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-5086

Опубликовано: 29 сент. 2006
Источник: nvd
CVSS2: 6.4
EPSS Низкий

Описание

Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pixel_motion:pixel_motion_blog:2.1.1:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.0114
Низкий

6.4 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.

EPSS

Процентиль: 78%
0.0114
Низкий

6.4 Medium

CVSS2

Дефекты

NVD-CWE-Other