includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2006-07-12T21:00:00

Updated: 2018-10-18T14:57:01

Reserved: 2006-07-12T00:00:00


Link: CVE-2006-3531

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2006-07-12T21:05:00.000

Modified: 2018-10-18T16:47:49.970


Link: CVE-2006-3531

JSON object: View

cve-icon Redhat Information

No data.