CVE Database
/

CVE-2009-2133

Back to search

CVE-2009-2133

Published: Jun 19, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrary web script or HTML via the (1) menu or (2) sort parameter to pivot/index.php, (3) the value of a check array parameter in a delete action to pivot/index.php, (4) the element name in a check array parameter in a delete action to pivot/index.php, (5) the edituser parameter in an edituser action to pivot/index.php, (6) the edit parameter in a templates action to pivot/index.php, (7) the blog parameter in a blog_edit1 action to pivot/index.php, (8) the cat parameter in a cat_edit action to pivot/index.php, (9) a certain form field in a doaction=1 request to pivot/index.php, (10) the url field in a my_weblog edit_prefs action to pivot/user.php, or (11) the username (aka name) field in a my_weblog reg_user action to pivot/user.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

8941
exploit
x_refsource_EXPLOIT-DB
35363
vdb-entry
x_refsource_BID
pivot-index-xss(51098)
vdb-entry
x_refsource_XF
35363
third-party-advisory
x_refsource_SECUNIA
pivot-visitor-xss(51099)
vdb-entry
x_refsource_XF
55085
vdb-entry
x_refsource_OSVDB
55086
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now