28645vdb entry
http://www.securityfocus.com/bid/28645 CVE-2008-1867
Blog PixelMotion - 'categorie' SQL Injection
Record summary
CVE-2008-1867 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie parameter to index.php, possibly related to include/requetesIndex.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBBlog PixelMotion - 'categorie' SQL InjectionExploitDB exploitby parad0xNot analyzed1 file
References
5ADV-2008-1121vdb entry
http://www.vupen.com/english/advisories/2008/1121/references blogpixelmotion-index-sql-injection(41668)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41668 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-1867 5382exploit
https://www.exploit-db.com/exploits/5382