CVE-2006-1426
Pixel Motion Blog - SQL Injection via Date Parameter and Authentication Bypass via Password Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-1426. PoCs published by DaBDouB-MoSiKaR.
AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in Pixel Motion software, where unsanitized user input in the 'date' parameter can be exploited to manipulate SQL queries. No actual exploit code is present, only a description and a sample URL.
Description
Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authentication via the (2) password parameter in admin/index.php.
Exploits (2)
The provided text describes a SQL injection vulnerability in Pixel Motion software, where unsanitized user input in the 'date' parameter can be exploited to manipulate SQL queries. No actual exploit code is present, only a description and a sample URL.
The exploit demonstrates SQL injection vulnerabilities in Pixel Motion due to improper input sanitization. The provided payload 'pass:' or 'x'='x' can bypass authentication or manipulate database queries.