4.3

CVE-2009-4788

Multiple open redirect vulnerabilities in Pligg 1.0.2 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the (1) return parameter to pligg/login.php and the (2) HTTP Referer header to user_settings.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pligg ≫ Pligg Cms Version <= 1.0.2
Pligg ≫ Pligg Cms Version 1.0.0
Pligg ≫ Pligg Cms Version 1.0.0 Update rc1
Pligg ≫ Pligg Cms Version 1.0.0 Update rc2
Pligg ≫ Pligg Cms Version 1.0.0 Update rc3
Pligg ≫ Pligg Cms Version 1.0.0 Update rc4
Pligg ≫ Pligg Cms Version 1.0.0 Update rc5
Pligg ≫ Pligg Cms Version 1.0.1
Pligg ≫ Pligg Cms Version 9.5
Pligg ≫ Pligg Cms Version 9.9
Pligg ≫ Pligg Cms Version 9.9.0
Pligg ≫ Pligg Cms Version 9.9.0 Update beta
Pligg ≫ Pligg Cms Version 9.9.5
Pligg ≫ Pligg Cms Version 9.9.5 Update beta
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.04% 0.595
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://holisticinfosec.org/content/view/130/45/
http://secunia.com/advisories/37349
Vendor Advisory
http://www.pligg.com/blog/775/pligg-cms-1-0-3-release/
Patch