Vulnerabilities > Pivot > Pivot > 1.30.rc2

DATE CVE VULNERABILITY TITLE RISK
2006-07-12 CVE-2006-3533 Input Validation vulnerability in Pivot 1.30Rc2
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) fg, (2) line1, (3) line2, (4) bg, (5) c1, (6) c2, (7) c3, and (8) c4 parameters in (a) includes/blogroll.php; (9) name and (10) js_name parameters in (b) includes/editor/edit_menu.php; and, even if register_globals is not enabled, the (11) h and (12) w parameters in (c) includes/photo.php.
network
pivot
5.8
2006-07-12 CVE-2006-3532 Input Validation vulnerability in Pivot 1.30Rc2
PHP file inclusion vulnerability in includes/edit_new.php in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a FTP URL or full file path in the Paths[extensions_path] parameter.
network
high complexity
pivot
5.1