- EPSS 4.17%
- Veröffentlicht 19.06.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url parameter, which reveals the installation path in an error message.
CVE-2009-2133
- EPSS 8.07%
- Veröffentlicht 19.06.2009 18:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrary web script or HTML via the (1) menu or (2) sort parameter to pivot/index.php, (3) the value of a check array parameter in a dele...
- EPSS 19.98%
- Veröffentlicht 10.07.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in search.php in Pivot 1.40.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the t parameter.
CVE-2006-3531
- EPSS 10.88%
- Veröffentlicht 12.07.2006 21:05:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and...
CVE-2006-3532
- EPSS 6.58%
- Veröffentlicht 12.07.2006 21:05:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
PHP file inclusion vulnerability in includes/edit_new.php in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a FTP URL or full file path in the Paths[extensions_path] parameter.
CVE-2006-3533
- EPSS 11.81%
- Veröffentlicht 12.07.2006 21:05:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) fg, (2) line1, (3) line2, (4) bg, (5) c1, (6) c2, (7) c3, a...