vendor:
Blog Pixel Motion
by:
DarkFig
7.5
CVSS
HIGH
PHP Code Execution, SQL Injection
CWE
Product Name: Blog Pixel Motion
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Blog Pixel Motion V2.1.1 PHP Code Execution / Create Admin
This exploit allows for PHP code execution and creation of admin credentials in Blog Pixel Motion V2.1.1. The vulnerability includes a PHP function that can be exploited to execute arbitrary code and bypass security measures.
Mitigation:
The vendor has not provided a patch for this vulnerability. To mitigate the risk, users are advised to update to a newer version of the software if available or consider alternative solutions.