Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Blog Pixel Motion 多个SQL注入漏洞
Vulnerability Description
Blog Pixel Motion 2.1.1远程攻击者通过以修改的(1)login和(2)pass参数直接请求insere_base.php来更改管理员用户的用户名和密码。
CVSS Information
N/A
Vulnerability Type
N/A