CVE-2008-1866
PixelMotion - RCE
Title source: llmDescription
admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request.
Exploits (2)
References (4)
Scores
EPSS
0.1511
EPSS Percentile
94.6%
Details
CWE
CWE-94
Status
published
Products (1)
pixel_motion/pixel_motion_blog
Published
Apr 17, 2008
Tracked Since
Feb 18, 2026