Lucene search

K
cveMitreCVE-2009-4787
HistoryApr 21, 2010 - 2:30 p.m.

CVE-2009-4787

2010-04-2114:30:00
CWE-352
mitre
web.nvd.nist.gov
33
csrf
pligg
vulnerability
hijacking
admin authentication

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.002

Percentile

52.8%

Multiple cross-site request forgery (CSRF) vulnerabilities in Pligg before 1.0.3 allow remote attackers to hijack the authentication of administrators for requests that create user accounts or have unspecified other impact.

Affected configurations

Nvd
Node
pliggpligg_cmsRange≤1.0.2
OR
pliggpligg_cmsMatch1.0.0
OR
pliggpligg_cmsMatch1.0.0rc1
OR
pliggpligg_cmsMatch1.0.0rc2
OR
pliggpligg_cmsMatch1.0.0rc3
OR
pliggpligg_cmsMatch1.0.0rc4
OR
pliggpligg_cmsMatch1.0.0rc5
OR
pliggpligg_cmsMatch1.0.1
VendorProductVersionCPE
pliggpligg_cms*cpe:2.3:a:pligg:pligg_cms:*:*:*:*:*:*:*:*
pliggpligg_cms1.0.0cpe:2.3:a:pligg:pligg_cms:1.0.0:*:*:*:*:*:*:*
pliggpligg_cms1.0.0cpe:2.3:a:pligg:pligg_cms:1.0.0:rc1:*:*:*:*:*:*
pliggpligg_cms1.0.0cpe:2.3:a:pligg:pligg_cms:1.0.0:rc2:*:*:*:*:*:*
pliggpligg_cms1.0.0cpe:2.3:a:pligg:pligg_cms:1.0.0:rc3:*:*:*:*:*:*
pliggpligg_cms1.0.0cpe:2.3:a:pligg:pligg_cms:1.0.0:rc4:*:*:*:*:*:*
pliggpligg_cms1.0.0cpe:2.3:a:pligg:pligg_cms:1.0.0:rc5:*:*:*:*:*:*
pliggpligg_cms1.0.1cpe:2.3:a:pligg:pligg_cms:1.0.1:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.6

Confidence

Low

EPSS

0.002

Percentile

52.8%