Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T19:41:03.680Z

Reserved: 2006-09-28T00:00:00

Link: CVE-2006-5086

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2006-09-29T00:07:00.000

Modified: 2025-04-09T00:30:58.490

Link: CVE-2006-5086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.