7.5
CVSSv2

CVE-2006-3531

Published: 12/07/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

includes/editor/insert_image.php in Pivot 1.30 RC2 and previous versions creates the authentication credentials from parameters, which allows remote malicious users to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

pivot pivot

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo "Pivot <= 130 RC2 privileges escalation / remote commands execution exploit\n"; echo "by rgod rgod@autisticiorg\n"; echo "site: retrogodaltervistaorg\n"; echo "dorks: \"Powered byPivot\"\n"; echo "version specific: \"Powered byPivot - 130 RC2\" +Rippersnapper\n\n"; /* works with regis ...