CVE-2006-3532

Pivot <1.30 RC2 - RCE

Title source: llm

Description

PHP file inclusion vulnerability in includes/edit_new.php in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a FTP URL or full file path in the Paths[extensions_path] parameter.

Exploits (1)

exploitdb WORKING POC
phpwebappsphp
https://www.exploit-db.com/exploits/1991

Scores

EPSS 0.0658
EPSS Percentile 91.2%

Details

Status published
Products (1)
pivot/pivot 1.30_rc2
Published Jul 12, 2006
Tracked Since Feb 18, 2026