Vulnerabilities > CVE-2006-2889 - Unspecified vulnerability in Pixelpost

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
pixelpost
nessus
exploit available

Summary

Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and leverage them to gain administrator privileges, via the (1) category or (2) archivedate parameter.

Vulnerable Configurations

Part Description Count
Application
Pixelpost
1

Exploit-Db

descriptionPixelpost <= 1-5rc1-2 Remote Privilege Escalation Exploit. CVE-2006-2889. Webapps exploit for php platform
idEDB-ID:1868
last seen2016-01-31
modified2006-06-03
published2006-06-03
reporterrgod
sourcehttps://www.exploit-db.com/download/1868/
titlePixelpost <= 1-5rc1-2 - Remote Privilege Escalation Exploit

Nessus

NASL familyCGI abuses
NASL idPIXELPOST_CATEGORY_SQL_INJECTION.NASL
descriptionThe remote host is running Pixelpost, a photo blog application based on PHP and MySQL. The version of Pixelpost installed on the remote fails to sanitize user-supplied input to the
last seen2020-06-01
modified2020-06-02
plugin id21645
published2006-06-06
reporterThis script is Copyright (C) 2006-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/21645
titlePixelpost index.php category Parameter SQL Injection