CVE-2006-3531 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 9.5% (pctl 95)
Patch early
A public exploit exists.
Description
includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 9.53% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-07-12 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| pivot | pivot |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Pivot 1.30 RC2 - Privilege Escalation / Remote Code Execution | 2006-07-07 |
References
- http://retrogod.altervista.org/pivot_130RC2_xpl.html
- http://secunia.com/advisories/20962
- http://securityreason.com/securityalert/1214
- http://www.osvdb.org/27126
- http://www.securityfocus.com/archive/1/439495/100/0/threaded
- http://www.securityfocus.com/bid/18881
- http://www.vupen.com/english/advisories/2006/2744
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27671
- http://retrogod.altervista.org/pivot_130RC2_xpl.html
- http://secunia.com/advisories/20962
- http://securityreason.com/securityalert/1214
- http://www.osvdb.org/27126
- http://www.securityfocus.com/archive/1/439495/100/0/threaded
- http://www.securityfocus.com/bid/18881
- http://www.vupen.com/english/advisories/2006/2744
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27671
→ the Explorer · watch your stack · NVD