Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2011-3793
Disclosure Date: September 24, 2011 (last updated October 04, 2023)
Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files.
0
Attacker Value
Unknown
CVE-2009-1067
Disclosure Date: March 26, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x parameter.
0
Attacker Value
Unknown
CVE-2009-1065
Disclosure Date: March 26, 2009 (last updated October 04, 2023)
SQL injection vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the x parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2009-1066
Disclosure Date: March 26, 2009 (last updated October 04, 2023)
SQL injection vulnerability in the referral function in admin/lib/lib_logs.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header in a request.
0