CVE-2006-1104
https://notcve.org/view.php?id=CVE-2006-1104
Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the showimage parameter in index.php; and the (2) USER_AGENT, (3) HTTP_REFERER, and (4) HTTP_HOST HTTP header fields as used in the book_vistor function in includes/functions.php. NOTE: the vendor has disputed some issues from the original disclosure, but due to the vagueness of the dispute, it is not clear whether the vendor is disputing this particular issue. • http://forum.pixelpost.org/showthread.php?t=3535 http://www.neosecurityteam.net/index.php?action=advisories&id=19 http://www.securityfocus.com/archive/1/426764/100/0/threaded http://www.securityfocus.com/bid/16964 http://www.vupen.com/english/advisories/2006/0823 https://exchange.xforce.ibmcloud.com/vulnerabilities/25044 https://exchange.xforce.ibmcloud.com/vulnerabilities/25046 •
CVE-2006-0409 – PixelPost 1.4.3 - User Comment HTML Injection
https://notcve.org/view.php?id=CVE-2006-0409
Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via the "Add Comment" field in a comment popup. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en index.php en Pixelpost Photoblog 1.4.3 permite a atacantes remotos inyectar 'script' web de su elección o HTML mediante el campo "Añadir Comentario" en una ventana emergente de comentario. • https://www.exploit-db.com/exploits/27123 http://evuln.com/vulns/45/summary.html http://secunia.com/advisories/18572 http://securitytracker.com/id?1015529 http://www.securityfocus.com/archive/1/423384/100/0/threaded http://www.securityfocus.com/bid/16362 http://www.vupen.com/english/advisories/2006/0309 https://exchange.xforce.ibmcloud.com/vulnerabilities/24261 •