CVE-2008-1867 describes a SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) that allows remote attackers to execute arbitrary SQL commands. This flaw, specifically affecting the 'categorie' parameter in index.php, could lead to unauthorized access to sensitive data, modification of database content, or even full system compromise. With a CVSS score of 7.5 (High) and a FAUCET Risk Score of 88/100, it represents a significant risk due to its low attack complexity and lack of authentication required. While not listed in CISA's KEV catalog, public exploit code exists on ExploitDB, indicating its potential for exploitation, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:pixel_motion:pixel_motion_blog:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.