4.3
CVSSv2

CVE-2009-2133

Published: 19/06/2009 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote malicious users to inject arbitrary web script or HTML via the (1) menu or (2) sort parameter to pivot/index.php, (3) the value of a check array parameter in a delete action to pivot/index.php, (4) the element name in a check array parameter in a delete action to pivot/index.php, (5) the edituser parameter in an edituser action to pivot/index.php, (6) the edit parameter in a templates action to pivot/index.php, (7) the blog parameter in a blog_edit1 action to pivot/index.php, (8) the cat parameter in a cat_edit action to pivot/index.php, (9) a certain form field in a doaction=1 request to pivot/index.php, (10) the url field in a my_weblog edit_prefs action to pivot/user.php, or (11) the username (aka name) field in a my_weblog reg_user action to pivot/user.php.

Vulnerable Product Search on Vulmon Subscribe to Product

pivot pivot 1.40.7

pivot pivot 1.40.4

Exploits

Pivot - XSS and HTML Injection Vulnerabilities Versions Affected: 1404 and 1407 (22nd March 2009) (newest) Info: Pivot is a web-based tool to help you maintain dynamic sites, like weblogs or online journals Pivot is released under the GPL so it is completely free to use It is written in PHP, and does not require additional libraries or data ...