Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-1426

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2006-1426
Last Modified 07 Mar 2011 09:33:04
Published 28 Mar 2006 03:02:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-1426

Summary

Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authentication via the (2) password parameter in admin/index.php.

Vulnerable Systems

Application

  • Pixel Motion Blog


References

VUPEN - ADV-2006-1135

BID - 17260

BUGTRAQ - 20060327 Blog Pixel Motion<=1.xx Authentication Bypass Vulnerability & SQL injection

SECUNIA - 19421

XF - pixelmotionblog-index-sql-injection(25481)

XF - pixelmotionblog-adminindex-security-bypass(25478)

OSVDB - 24169

OSVDB - 24168


Last Updated: 27 May 2016 10:42:02