CVE-2006-3531

Pivot 1.30 RC2 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-3531.

AI-analyzed exploit summary This exploit leverages a privilege escalation vulnerability in Pivot CMS <= 1.30 RC2 due to improper handling of global variables when register_globals is enabled. It allows remote command execution by manipulating the $Pivot_Vars and $Users arrays to escalate privileges and upload malicious PHP files.

Description

includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.

Exploits (1)

exploitdb WORKING POC
phpwebappsphp
https://www.exploit-db.com/exploits/1991

This exploit leverages a privilege escalation vulnerability in Pivot CMS <= 1.30 RC2 due to improper handling of global variables when register_globals is enabled. It allows remote command execution by manipulating the $Pivot_Vars and $Users arrays to escalate privileges and upload malicious PHP files.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Pivot CMS <= 1.30 RC2
No auth needed
Prerequisites: register_globals=On · PHP environment
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/439495/100/0/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2744
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27671
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20962
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18881
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1214
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/27126

Scores

EPSS 0.1088
EPSS Percentile 93.6%

Details

Status published
Products (1)
pivot/pivot < 1.30_rc2
Published Jul 12, 2006
Tracked Since Feb 18, 2026