![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.900579 |
Category: | Web application abuses |
Title: | Pivot <= 1.40.7 XSS Vulnerability |
Summary: | Pivot is prone to a cross-site scripting (XSS) vulnerability. |
Description: | Summary: Pivot is prone to a cross-site scripting (XSS) vulnerability. Vulnerability Insight: - The input passed into several parameters in the pivot/index.php and pivot/user.php is not sanitised before being processed. - An error in pivot/tb.php while processing invalid url parameter reveals sensitive information such as the installation path in an error message. Vulnerability Impact: Successful exploitation will allow remote attackers to bypass security restrictions by gaining sensitive information, execute arbitrary html or webscript code and redirect the user to other malicious sites. Affected Software/OS: Pivot version 1.40.7 and prior. Solution: No known solution was made available for at least one year since the disclosure of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer release, disable respective features, remove the product or replace the product by another one. CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-2133 BugTraq ID: 35363 http://www.securityfocus.com/bid/35363 Bugtraq: 20090612 [InterN0T] Pivot 1.40.4-7 - Multiple Vulnerabilities (Google Search) http://www.securityfocus.com/archive/1/504300/100/0/threaded https://www.exploit-db.com/exploits/8941 http://forum.intern0t.net/intern0t-advisories/1119-intern0t-pivot-1-40-4-7-multiple-vulnerabilities.html http://osvdb.org/55085 http://osvdb.org/55086 http://secunia.com/advisories/35363 XForce ISS Database: pivot-index-xss(51098) https://exchange.xforce.ibmcloud.com/vulnerabilities/51098 XForce ISS Database: pivot-visitor-xss(51099) https://exchange.xforce.ibmcloud.com/vulnerabilities/51099 Common Vulnerability Exposure (CVE) ID: CVE-2009-2134 |
Copyright | Copyright (C) 2009 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |