Логотип exploitDog
bind:CVE-2006-3531
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2006-3531

Количество 3

Количество 3

nvd логотип

CVE-2006-3531

около 19 лет назад

includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2006-3531

около 19 лет назад

includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates ...

CVSS2: 7.5
EPSS: Средний
github логотип

GHSA-286q-p2xc-rmjg

больше 3 лет назад

includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2006-3531

includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.

CVSS2: 7.5
11%
Средний
около 19 лет назад
debian логотип
CVE-2006-3531

includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates ...

CVSS2: 7.5
11%
Средний
около 19 лет назад
github логотип
GHSA-286q-p2xc-rmjg

includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.

11%
Средний
больше 3 лет назад

Уязвимостей на страницу