Back to Database
Status published
Medium
CVE-2009-2134
pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to...
Vulnerability Description
pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url parameter, which reveals the installation path in an error message.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-2134
Credits & Attribution
No credits recorded in the NVD database.
References
More from pivot
View All →CVE-2009-2133
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7...
Medium
4.3
CVE-2008-3128
Directory traversal vulnerability in search.php in Pivot 1.40.5 allows remote...
Medium
5
CVE-2006-3533
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and...
Medium
5.8
CVE-2006-3532
PHP file inclusion vulnerability in includes/edit_new.php in Pivot 1.30 RC2...
Medium
5.1
CVE-2006-3531
includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication...
High
7.5
Affected Vendor
pivot
View all reports →Affected Software
pivot
Vulnerable Versions:
1.40.4, 1.40.7
Timeline
Official Publish:
June 19th, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.