Summary
Pivot is a set of PHP scripts designed to maintain dynamic web pages.
There is a flaw in the file module_db.php which may let an attacker execute arbitrary commands on the remote host by forcing the remote Pivot installation to include a PHP file hosted on an arbitrary third-party website.
Solution
Upgrade to Pivot 1.14.1 or disable this CGI altogether
Severity
Classification
-
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Apache Tomcat Windows Installer Privilege Escalation Vulnerability
- Apache Archiva Multiple Remote Command Execution Vulnerabilities
- ASP-Dev XM Event Diary Multiple Vulnerabilities
- AWStats Totals 'sort' Parameter Remote Command Execution Vulnerabilities
- Apache Axis2 Document Type Declaration Processing Security Vulnerability