PT-2009-2437 · Pligg · Pligg Cms

Published

2009-08-13

·

Updated

2017-08-17

·

CVE-2008-6968

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Pligg CMS version 9.9.5
Description: The issue concerns SQL injection vulnerabilities in the submit.php file. Remote attackers can execute arbitrary SQL commands via the category and id parameters.
Recommendations: For Pligg CMS version 9.9.5, consider restricting access to the submit.php file until a patch is available. As a temporary workaround, avoid using the category and id parameters in the affected API endpoint.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6968

Affected Products

Pligg Cms