CVE-2006-3533 Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and earlier when register_globals is enabled allow remote attackers to inject arbitrary web script or HTML via the (1) fg (2) line1 (3) line2 (4) bg (5) c1 (6) c2 (7) c3 and (8) c4 parameters in (a) includes/blogroll.php; (9) name and (10) js_name parameters in (b) includes/editor/edit_menu.php; and even if register_globals is not enabled the (11) h and (12) w parameters in (c) includes/photo.php.
Reference
http://retrogod.altervista.org/pivot_130RC2_xpl.html http://secunia.com/advisories/20962 http://securityreason.com/securityalert/1214 http://www.osvdb.org/27127 http://www.osvdb.org/27128 http://www.osvdb.org/27129 http://www.securityfocus.com/archive/1/439495/100/0/threaded http://www.securityfocus.com/bid/18881 http://www.vupen.com/english/advisories/2006/2744 https://exchange.xforce.ibmcloud.com/vulnerabilities/27672
Share on: