Vulnerabilities > CVE-2006-2889 - SQL Injection vulnerability in Pixelpost

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
pixelpost
nessus
exploit available

Summary

Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and leverage them to gain administrator privileges, via the (1) category or (2) archivedate parameter.

Vulnerable Configurations

Part Description Count
Application
Pixelpost
1

Exploit-Db

descriptionPixelpost <= 1-5rc1-2 Remote Privilege Escalation Exploit. CVE-2006-2889. Webapps exploit for php platform
idEDB-ID:1868
last seen2016-01-31
modified2006-06-03
published2006-06-03
reporterrgod
sourcehttps://www.exploit-db.com/download/1868/
titlePixelpost <= 1-5rc1-2 - Remote Privilege Escalation Exploit

Nessus

NASL familyCGI abuses
NASL idPIXELPOST_CATEGORY_SQL_INJECTION.NASL
descriptionThe remote host is running Pixelpost, a photo blog application based on PHP and MySQL. The version of Pixelpost installed on the remote fails to sanitize user-supplied input to the
last seen2020-06-01
modified2020-06-02
plugin id21645
published2006-06-06
reporterThis script is Copyright (C) 2006-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/21645
titlePixelpost index.php category Parameter SQL Injection