PT-2010-1597 · Pligg · Pligg
Publicado
2010-04-21
·
Atualizado
2010-06-03
·
CVE-2009-4788
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Pligg versions 1.0.2 and earlier
Description
The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This can be achieved via the
return parameter to "pligg/login.php" and the HTTP Referer header to "user settings.php".Recommendations
For Pligg versions 1.0.2 and earlier, as a temporary workaround, consider restricting access to the "pligg/login.php" and "user settings.php" pages until a patch is available. Avoid using the
return parameter in the "pligg/login.php" endpoint until the issue is resolved.Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pligg