Skip to main content

Vendor/product archive

pligg / pligg_cms CVEs

Beta · best-effort

43 CVEs tagged to pligg / pligg_cms3 Critical, 28 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2011-5023

Published Dec 29, 2011

Cross-site scripting (XSS) vulnerability in Pligg CMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the search program, a different vul…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5022

Published Dec 29, 2011

SQL injection vulnerability in search.php in Pligg CMS 1.1.2 allows remote attackers to execute arbitrary SQL commands via the status parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-3986

Published Nov 3, 2011

Cross-site scripting (XSS) vulnerability in Pligg before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3794

Published Sep 24, 2011

Pligg CMS 1.1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3013

Published Aug 16, 2010

SQL injection vulnerability in groupadmin.php in Pligg before 1.1.1 allows remote attackers to execute arbitrary SQL commands via the role parameter, a different vulnerability tha…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-2577

Published Aug 16, 2010

Multiple SQL injection vulnerabilities in Pligg before 1.1.1 allow remote attackers to execute arbitrary SQL commands via the title parameter to (1) storyrss.php or (2) story.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4788

Published Apr 21, 2010

Multiple open redirect vulnerabilities in Pligg 1.0.2 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the (1) return p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4787

Published Apr 21, 2010

Multiple cross-site request forgery (CSRF) vulnerabilities in Pligg before 1.0.3 allow remote attackers to hijack the authentication of administrators for requests that create use…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4786

Published Apr 21, 2010

Multiple cross-site scripting (XSS) vulnerabilities in Pligg before 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to (1) admin/ad…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7091

Published Aug 26, 2009

Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to vote.php, which is not properl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7090

Published Aug 26, 2009

Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .. (dot dot) in the $tb_url va…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7089

Published Aug 26, 2009

Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action to us…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6968

Published Aug 13, 2009

Multiple SQL injection vulnerabilities in submit.php in Pligg CMS 9.9.5 allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) id parameters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5739

Published Dec 26, 2008

SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQL commands via the url parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3572

Published Aug 10, 2008

Cross-site scripting (XSS) vulnerability in index.php in Pligg 9.9.5 allows remote attackers to inject arbitrary web script or HTML via the category parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3366

Published Jul 30, 2008

SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2008…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1774

Published Apr 14, 2008

SQL injection vulnerability in editlink.php in Pligg 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5579

Published Oct 18, 2007

login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote attackers with knowledge of a username to reset that user's…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-43 of 43 CVEsPage 2 of 2