includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-07-12T21:00:00

Updated: 2024-08-07T18:30:34.313Z

Reserved: 2006-07-12T00:00:00

Link: CVE-2006-3531

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2006-07-12T21:05:00.000

Modified: 2018-10-18T16:47:49.970

Link: CVE-2006-3531

cve-icon Redhat

No data.