| InterN0T - Advisories Advisories that are found by members of InterN0T. |
#1
| ||||
| ||||
| Pivot 1.40.4-7 - Multiple Vulnerabilities Pivot - XSS and HTML Injection Vulnerabilities Versions Affected: 1.40.4 and 1.40.7 (22nd March 2009) (newest) Info: Pivot is a web-based tool to help you maintain dynamic sites, like weblogs or online journals. Pivot is released under the GPL so it is completely free to use. It is written in PHP, and does not require additional libraries or databases to function. Credits: InterN0T External Links: http://www.pivotlog.net/ -:: The Advisory ::- Quote:
The solution for this is not simple at all. I suggest a complete review of the entire codebase. Conclusion: When we first checked the platform for vulnerabilities we had apparently installed an old version, so we updated to the newest version which apparently had some "XSS-bug fixed", strangely enough all the vulnerabilities we found are still there. Disclosure Information: - Vulnerabilities found, researched and confirmed between 5th to 10th June. - Advisory finished and published on InterN0T the 12th June. - Vendor and Buqtraq (SecurityFocus) contacted the 12th June. All of the best, MaXe
__________________ ![]() Quote:
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
| |
LinkBacks (?)
LinkBack to this Thread: http://forum.intern0t.net/intern0t-advisories/1119-pivot-1-40-4-7-multiple-vulnerabilities.html | ||||
| Posted By | For | Type | Date | |
| US-CERT Cyber Security Bulletin SB09-180 -- Vulnerability Summary for the Week of June 22, 2009 | This thread | Refback | 30th January 2010 19:53 | |
| Pivot Multiple Cross-Site Scripting and HTML Injection Vulnerabilities | This thread | Refback | 19th July 2009 18:26 | |
| US-CERT Cyber Security Bulletin SB09-180 -- Vulnerability Summary for the Week of June 22, 2009 | This thread | Refback | 29th June 2009 16:49 | |
| CVE - CVE-2009-2134 (under review) | This thread | Refback | 26th June 2009 19:55 | |
| Pivot Multiple Cross Site Scripting And HTML Injection Vulnerabilities | This thread | Refback | 15th June 2009 18:03 | |
| Pivot Multiple Cross-Site Scripting Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | This thread | Refback | 15th June 2009 13:54 | |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| AMember 3.1.7 - Multiple Vulnerabilities | MaXe | InterN0T - Advisories | 11 | 27th September 2009 18:09 |
| transLucid 1.75 - Multiple Vulnerabilities | MaXe | InterN0T - Advisories | 0 | 12th June 2009 21:02 |
| TBDev 01-01-2008 - Multiple Vulnerabilities | MaXe | InterN0T - Advisories | 0 | 12th June 2009 20:58 |
| Thelia 1.3.5 Multiple Vulnerabilities Exploit | hestas | Exploits, Vulnerabilities & PoCs | 0 | 7th July 2008 02:50 |