Lucene search

K
cveMitreCVE-2008-7091
HistoryAug 26, 2009 - 2:24 p.m.

CVE-2008-7091

2009-08-2614:24:17
CWE-89
mitre
web.nvd.nist.gov
24
cve-2008-7091
sql injection
pligg 9.9
security vulnerability
remote attack

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.8

Confidence

Low

EPSS

0.003

Percentile

69.8%

Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to vote.php, which is not properly handled in libs/link.php; (2) id parameter to trackback.php; (3) an unspecified parameter to submit.php; (4) requestTitle variable in a query to story.php; (5) requestID and (6) requestTitle variables in recommend.php; (7) categoryID parameter to cloud.php; (8) title parameter to out.php; (9) username parameter to login.php; (10) id parameter to cvote.php; and (11) commentid parameter to edit.php.

Affected configurations

Nvd
Node
pliggpligg_cmsRange9.9.0
OR
pliggpligg_cmsMatch9.5
OR
pliggpligg_cmsMatch9.9.0beta
VendorProductVersionCPE
pliggpligg_cms*cpe:2.3:a:pligg:pligg_cms:*:*:*:*:*:*:*:*
pliggpligg_cms9.5cpe:2.3:a:pligg:pligg_cms:9.5:*:*:*:*:*:*:*
pliggpligg_cms9.9.0cpe:2.3:a:pligg:pligg_cms:9.9.0:beta:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

8.8

Confidence

Low

EPSS

0.003

Percentile

69.8%

Related for CVE-2008-7091