CVE-2006-3533
Pivot 1.30 RC2 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) fg, (2) line1, (3) line2, (4) bg, (5) c1, (6) c2, (7) c3, and (8) c4 parameters in (a) includes/blogroll.php; (9) name and (10) js_name parameters in (b) includes/editor/edit_menu.php; and, even if register_globals is not enabled, the (11) h and (12) w parameters in (c) includes/photo.php.
Exploits (1)
References (10)
Scores
EPSS
0.1181
EPSS Percentile
93.7%
Details
Status
published
Products (1)
pivot/pivot
1.30_rc2
Published
Jul 12, 2006
Tracked Since
Feb 18, 2026