Pixel Motion's vulnerability footprint centers on its blog product and is characterized by common web-application vulnerability classes including improper authentication, cross-site scripting, SQL injection, and code injection. The vendor's disclosures show a notable tendency toward public exploit availability, reflecting the accessibility and relative straightforwardness of remediating web-tier flaws once disclosed. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pixel Motion over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5085HIGH Static code injection vulnerability in config.php in Blog Pixel Motion 2.1.1 allows remote attackers to execute arbitrary PHP code via the nom_blog parameter, which is injected int | Sep 29, 2006 | 7.5 | 52 | NO | YES |
CVE-2008-1866HIGH admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZI | Apr 17, 2008 | 9.0 | 36 | NO | YES |
CVE-2008-1868HIGH admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resu | Apr 17, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-1867HIGH SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie parameter to index.php, possibly | Apr 17, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-1426HIGH Multiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in index.php or bypass authenticatio | Mar 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-5086MEDIUM Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass | Sep 29, 2006 | 6.4 | 25 | NO | YES |
CVE-2008-1986MEDIUM Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours pa | Apr 27, 2008 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pixel Motion.
Media articles that mention a CVE ID that affects a product developed by Pixel Motion — matched by CVE ID, not by vendor name.