← Vulnerability feed

Vulnerability record · CVE-2008-1866 · published 17 April 2008

CVE-2008-1866: Pixel motion blog code injection vulnerability

Pixel Motion · Pixel Motion Blog

admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request.

9.0 CVSS 2.0 High EPSS 5.2% · top 7.8% CWE-94 · Code injection
9.0CVSS 2.0 base score
5.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request.

AV:N/AC:L/Au:S/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1866 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2008-1867Pixel motion blog sql injection vulnerabilitySQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie p…EPSS 0.97%7.5CVE-2008-1868Pixel motion blog improper authentication vulnerabilityadmin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database b…EPSS 2.6%7.5CVE-2006-5085Blog Pixel Motion config.php static code injection enables PHP executionBlog Pixel Motion 2.1.1 writes the nom_blog parameter from config.php into include/variables.php without sanitization, allowing injected PHP code to …EPSS 47%analysed7.5CVE-2006-1426Pixel motion blog vulnerabilityMultiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in in…EPSS 2.0%6.4CVE-2006-5086Pixel motion blog vulnerabilityBlog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with m…EPSS 1.2%4.3CVE-2008-1986Pixel motion blog cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web …EPSS 1.4%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed

Source: NIST National Vulnerability Database (record CVE-2008-1866), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.