CVE-2008-1867

critical

Description

SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie parameter to index.php, possibly related to include/requetesIndex.php.

References

https://www.exploit-db.com/exploits/5382

https://exchange.xforce.ibmcloud.com/vulnerabilities/41668

http://www.vupen.com/english/advisories/2008/1121/references

Details

Source: Mitre, NVD

Published: 2008-04-17

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00144