peter bassill · operator
$ cve CVE-2006-3531 JSON

CVE-2006-3531 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 9.5% (pctl 95)

Patch early

A public exploit exists.

Description

includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS9.53% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2006-07-12
Last modified2026-06-16

Affected (1)

VendorProduct
pivotpivot

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD