File Inclusion Vulnerability in Pivot

Summary
Pivot is a set of PHP scripts designed to maintain dynamic web pages. There is a flaw in the file module_db.php which may let an attacker execute arbitrary commands on the remote host by forcing the remote Pivot installation to include a PHP file hosted on an arbitrary third-party website.
Solution
Upgrade to Pivot 1.14.1 or disable this CGI altogether