CVE-2009-2134

Pivot <1.40.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url parameter, which reveals the installation path in an error message.

Exploits (1)

exploitdb WRITEUP VERIFIED
by intern0t · textwebappsphp
https://www.exploit-db.com/exploits/8941

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8941
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/504300/100/0/threaded

Scores

EPSS 0.0417
EPSS Percentile 88.7%

Details

CWE
CWE-200
Status published
Products (2)
pivot/pivot 1.40.4
pivot/pivot 1.40.7
Published Jun 19, 2009
Tracked Since Feb 18, 2026