PT-2009-2437 · Pligg · Pligg Cms
Published
2009-08-13
·
Updated
2017-08-17
·
CVE-2008-6968
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Pligg CMS version 9.9.5
Description:
The issue concerns SQL injection vulnerabilities in the submit.php file. Remote attackers can execute arbitrary SQL commands via the
category and id parameters.Recommendations:
For Pligg CMS version 9.9.5, consider restricting access to the submit.php file until a patch is available. As a temporary workaround, avoid using the
category and id parameters in the affected API endpoint.Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pligg Cms