Pixelpost 1-5rc1-2 and earlier, when registerglobals is enabled, allows remote attackers to gain administrator privileges and conduct other attacks by setting the SESSION["pixelpostadmin"] parameter to 1 in calls to admin scripts such as admin/viewinfo.php.
Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and leverage them to gain administrator privileges, via the (1) category or (2) archivedate parameter.
Cross-site scripting (XSS) vulnerability in admin/index.php for Pixelpost 1-5rc1-2 and earlier allows remote attackers to inject arbitrary HTML or web script via the loginmessage parameter.