First published: Wed Jun 07 2006(Updated: )
Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and leverage them to gain administrator privileges, via the (1) category or (2) archivedate parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pixelpost | <=1.5_rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2889 is classified as a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2006-2889, you should upgrade to Pixelpost version 1.5_rc2 or later, which addresses these SQL injection vulnerabilities.
CVE-2006-2889 contains multiple SQL injection vulnerabilities in the index.php file.
The vulnerabilities in CVE-2006-2889 can be exploited through the 'category' and 'archivedate' parameters.
Yes, CVE-2006-2889 can be exploited by attackers to gain administrator privileges on vulnerable systems.