pixelpost records
17 published records for vendor pixelpost.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
17 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2009-4899No exploit | pixelpost 1.7.1 has SQL injectionpixelpost · pixelpost · CWE-89 | Critical9.8 | — | 1.3% | Oct 28, 2019 |
35Monitor | CVE-2010-3305No exploit | Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.pixelpost · pixelpost · CWE-352 | High8.8 | — | 1.0% | Nov 12, 2019 |
30Monitor | CVE-2006-1104No exploit | Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) pixelpost · pixelpost | High7.5 | — | 1.5% | Mar 9, 2006 |
29Monitor | CVE-2018-0604No exploit | Pixelpost v1.7.3 and earlier allows remote code execution via unspecified vectors.pixelpost · pixelpost | High7.2 | — | 1.8% | Jun 26, 2018 |
28Monitor | CVE-2008-3365Proof of concept | Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to ipixelpost · pixelpost · CWE-22 | Medium6.8 | — | 3.8% | Jul 30, 2008 |
28Monitor | CVE-2008-0358Proof of concept | SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id paramepixelpost · pixelpost · CWE-89 | Medium6.8 | — | 2.2% | Jan 18, 2008 |
28Monitor | CVE-2018-0606No exploit | SQL injection vulnerability in the Pixelpost v1.7.3 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via pixelpost · pixelpost · CWE-89 | High7.2 | — | 1.1% | Jun 26, 2018 |
26Monitor | CVE-2011-1100Proof of concept | Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commapixelpost · pixelpost · CWE-89 | Medium6.5 | — | 1.3% | Feb 25, 2011 |
24Monitor | CVE-2009-4900No exploit | pixelpost 1.7.1 has XSSpixelpost · pixelpost · CWE-79 | Medium6.1 | — | 1.0% | Oct 28, 2019 |
24Monitor | CVE-2018-0605No exploit | Cross-site scripting vulnerability in Pixelpost v1.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecpixelpost · pixelpost · CWE-79 | Medium6.1 | — | 0.8% | Jun 26, 2018 |
21Monitor | CVE-2006-1105No exploit | Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, wpixelpost · pixelpost | Medium5.0 | — | 1.7% | Mar 9, 2006 |
20Monitor | CVE-2006-2890No exploit | Pixelpost 1-5rc1-2 and earlier, when register_globals is enabled, allows remote attackers to gain administrator privileges and conduct otherpixelpost · pixelpost | Medium5.1 | — | 1.5% | Jun 7, 2006 |
20Monitor | CVE-2011-3792No exploit | Pixelpost 1.7.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation pixelpost · pixelpost · CWE-200 | Medium5.0 | — | 1.2% | Sep 23, 2011 |
20Monitor | CVE-2006-2889Proof of concept | Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commanpixelpost · pixelpost | Medium5.1 | — | 1.1% | Jun 7, 2006 |
18Monitor | CVE-2006-0409Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script orpixelpost · photoblog | Medium4.3 | — | 2.0% | Jan 24, 2006 |
18Monitor | CVE-2006-1106No exploit | Cross-site scripting (XSS) vulnerability in Pixelpost 1.5 beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML pixelpost · pixelpost | Medium4.3 | — | 2.0% | Mar 9, 2006 |
11Monitor | CVE-2006-2891No exploit | Cross-site scripting (XSS) vulnerability in admin/index.php for Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject arbitrary Hpixelpost · pixelpost | Low2.6 | — | 1.9% | Jun 7, 2006 |
- CVE-2009-489939Monitor
pixelpost 1.7.1 has SQL injection
CriticalCVSS 9.8No exploitEPSS 1%pixelpost · pixelpostOct 28, 2019
- CVE-2010-330535Monitor
Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.
HighCVSS 8.8No exploitEPSS 1%pixelpost · pixelpostNov 12, 2019
- CVE-2006-110430Monitor
Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1)
HighCVSS 7.5No exploitEPSS 2%pixelpost · pixelpostMar 9, 2006
- CVE-2018-060429Monitor
Pixelpost v1.7.3 and earlier allows remote code execution via unspecified vectors.
HighCVSS 7.2No exploitEPSS 2%pixelpost · pixelpostJun 26, 2018
- CVE-2008-336528Monitor
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to i
MediumCVSS 6.8Proof of conceptEPSS 4%pixelpost · pixelpostJul 30, 2008
- CVE-2008-035828Monitor
SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parame
MediumCVSS 6.8Proof of conceptEPSS 2%pixelpost · pixelpostJan 18, 2008
- CVE-2018-060628Monitor
SQL injection vulnerability in the Pixelpost v1.7.3 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via
HighCVSS 7.2No exploitEPSS 1%pixelpost · pixelpostJun 26, 2018
- CVE-2011-110026Monitor
Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL comma
MediumCVSS 6.5Proof of conceptEPSS 1%pixelpost · pixelpostFeb 25, 2011
- CVE-2009-490024Monitor
pixelpost 1.7.1 has XSS
MediumCVSS 6.1No exploitEPSS 1%pixelpost · pixelpostOct 28, 2019
- CVE-2018-060524Monitor
Cross-site scripting vulnerability in Pixelpost v1.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspec
MediumCVSS 6.1No exploitEPSS 1%pixelpost · pixelpostJun 26, 2018
- CVE-2006-110521Monitor
Pixelpost 1.5 beta 1 and earlier allows remote attackers to obtain configuration information via a direct request to includes/phpinfo.php, w
MediumCVSS 5.0No exploitEPSS 2%pixelpost · pixelpostMar 9, 2006
- CVE-2006-289020Monitor
Pixelpost 1-5rc1-2 and earlier, when register_globals is enabled, allows remote attackers to gain administrator privileges and conduct other
MediumCVSS 5.1No exploitEPSS 1%pixelpost · pixelpostJun 7, 2006
- CVE-2011-379220Monitor
Pixelpost 1.7.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation
MediumCVSS 5.0No exploitEPSS 1%pixelpost · pixelpostSep 23, 2011
- CVE-2006-288920Monitor
Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL comman
MediumCVSS 5.1Proof of conceptEPSS 1%pixelpost · pixelpostJun 7, 2006
- CVE-2006-040918Monitor
Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or
MediumCVSS 4.3Proof of conceptEPSS 2%pixelpost · photoblogJan 24, 2006
- CVE-2006-110618Monitor
Cross-site scripting (XSS) vulnerability in Pixelpost 1.5 beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3No exploitEPSS 2%pixelpost · pixelpostMar 9, 2006
- CVE-2006-289111Monitor
Cross-site scripting (XSS) vulnerability in admin/index.php for Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject arbitrary H
LowCVSS 2.6No exploitEPSS 2%pixelpost · pixelpostJun 7, 2006