TROYANOSYVIRUS
Retour aux CVEs

CVE-2006-3531

N/A

Description

includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.

Details CVE

Score CVSS v3.1N/A
Publie7/12/2006
Derniere modification4/16/2026
Sourcenvd
Observations honeypot0

Produits affectes

pivot:pivot

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.