← Vulnerability feed

Vulnerability record · CVE-2008-1868 · published 17 April 2008

CVE-2008-1868: Pixel motion blog improper authentication vulnerability

Pixel Motion · Pixel Motion Blog

admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information.

7.5 CVSS 2.0 High EPSS 2.6% · top 15.2% CWE-287 · Improper authentication
7.5CVSS 2.0 base score
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1868 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2008-1866Pixel motion blog code injection vulnerabilityadmin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to uploa…EPSS 5.2%7.5CVE-2008-1867Pixel motion blog sql injection vulnerabilitySQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie p…EPSS 0.97%7.5CVE-2006-5085Blog Pixel Motion config.php static code injection enables PHP executionBlog Pixel Motion 2.1.1 writes the nom_blog parameter from config.php into include/variables.php without sanitization, allowing injected PHP code to …EPSS 47%analysed7.5CVE-2006-1426Pixel motion blog vulnerabilityMultiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in in…EPSS 2.0%6.4CVE-2006-5086Pixel motion blog vulnerabilityBlog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with m…EPSS 1.2%4.3CVE-2008-1986Pixel motion blog cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web …EPSS 1.4%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed

Source: NIST National Vulnerability Database (record CVE-2008-1868), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.