6.4

CVE-2006-5086

Exploit
Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters.  NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pixel MotionPixel Motion Blog Version2.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.06% 0.602
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://acid-root.new.fr/poc/12060927.txt
Exploit
http://secunia.com/advisories/22163
Vendor Advisory
http://securityreason.com/securityalert/1653
http://www.securityfocus.com/archive/1/447167/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/29222