Description
Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2006-5071 | Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T19:41:03.680Z
Reserved: 2006-09-28T00:00:00.000Z
Link: CVE-2006-5086
No data.
Status : Modified
Published: 2006-09-29T00:07:00.000
Modified: 2026-04-23T00:35:47.467
Link: CVE-2006-5086
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD