First published: Fri Feb 25 2011(Updated: )
Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) findfid, (2) id, (3) selectfcat, (4) selectfmon, or (5) selectftag parameter in an images action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pixelpost | =1.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1100 is classified as a high severity vulnerability due to its potential for remote SQL command execution.
To fix CVE-2011-1100, update Pixelpost to the latest version that patches this vulnerability.
CVE-2011-1100 affects users of Pixelpost version 1.7.3 who are authenticated and have access to the admin panel.
CVE-2011-1100 is an SQL injection vulnerability that allows execution of arbitrary SQL commands.
CVE-2011-1100 involves the admin/index.php component of Pixelpost where specific parameters are exploited.