PT-2010-1597 · Pligg · Pligg
Published
2010-04-21
·
Updated
2010-06-03
·
CVE-2009-4788
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Pligg versions 1.0.2 and earlier
Description
The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. This can be achieved via the
return parameter to "pligg/login.php" and the HTTP Referer header to "user settings.php".Recommendations
For Pligg versions 1.0.2 and earlier, as a temporary workaround, consider restricting access to the "pligg/login.php" and "user settings.php" pages until a patch is available. Avoid using the
return parameter in the "pligg/login.php" endpoint until the issue is resolved.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pligg