Nessus Plugin #12282

Plugin Index

Note: This file has been created from a downloaded version of the Nessus Plugins from http://www.nessus.org/. Therefore, the information here can be outdated.

File Inclusion Vulnerability in Pivot

Family:
CGI abuses
Category:
infos
Copyright:
This script is Copyright (C) 2004 Noam Rathaus
Summary:
Detect Pivot File Inclusion Vulnerability
Version:
$Revision: 1.2 $
Cve_id:
-
Bugtraq_id:
-
Xrefs:
-
Description:

Pivot is a set of PHP scripts designed to maintain dynamic web pages.

There is a flaw in the file module_db.php which may let an attacker execute
arbitrary commands on the remote host by forcing the remote Pivot installation
to include a PHP file hosted on an arbitrary third-party website.

Solution : Upgrade to Pivot 1.14.1 or disable this CGI altogether
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.