PT-2006-4406 · Pivot · Pivot

Rgod

·

Published

2006-07-12

·

Updated

2018-10-18

·

CVE-2006-3531

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Pivot versions 1.30 RC2 and earlier
Description The issue allows remote attackers to obtain privileges and upload arbitrary files by modifying certain parameters. This is achieved by creating authentication credentials from parameters in the includes/editor/insert image.php file. The vulnerable parameters include pass and session, as well as pass and userlevel indices of the Pivot Vars[] or Users[] array parameters.
Recommendations For Pivot versions 1.30 RC2 and earlier, consider disabling the includes/editor/insert image.php file until a patch is available to prevent remote attackers from obtaining privileges and uploading arbitrary files. Restrict access to the Pivot Vars[] and Users[] array parameters to minimize the risk of exploitation. Avoid using the pass and session parameters, as well as the pass and userlevel indices, in the affected file until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3531

Affected Products

Pivot