CVE-2006-5086

pixel_motion_blog 2.1.1 - Unauthenticated Admin Credential Change via insere_base.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5086. PoCs published by DarkFig.

AI-analyzed exploit summary This exploit targets Blog Pixel Motion V2.1.1, leveraging PHP code execution via stripslashes and SQL injection via urldecode. It provides options to execute arbitrary commands or create an admin account.

Description

Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DarkFig · perlwebappsphp
https://www.exploit-db.com/exploits/2441

This exploit targets Blog Pixel Motion V2.1.1, leveraging PHP code execution via stripslashes and SQL injection via urldecode. It provides options to execute arbitrary commands or create an admin account.

Classification
Working Poc 95%
Attack Type
Rce | Sqli
Complexity
Moderate
Reliability
Reliable
Target: Blog Pixel Motion V2.1.1
No auth needed
Prerequisites: Network access to the target · Target running Blog Pixel Motion V2.1.1
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22163
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/447167/100/0/threaded
Exploit x_refsource_misc
http://acid-root.new.fr/poc/12060927.txt
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1653
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/29222

Scores

EPSS 0.0106
EPSS Percentile 60.2%

Details

Status published
Products (1)
pixel_motion/pixel_motion_blog 2.1.1
Published Sep 29, 2006
Tracked Since Feb 18, 2026