CVE-2008-1866

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
17/04/2008
Last modified:
09/04/2025

Description

admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pixel_motion:pixel_motion_blog:*:*:*:*:*:*:*:*