peter bassill · operator
$ cve CVE-2008-7091 JSON

CVE-2008-7091 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.1% (pctl 81)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to vote.php, which is not properly handled in libs/link.php; (2) id parameter to trackback.php; (3) an unspecified parameter to submit.php; (4) requestTitle variable in a query to story.php; (5) requestID and (6) requestTitle variables in recommend.php; (7) categoryID parameter to cloud.php; (8) title parameter to out.php; (9) username parameter to login.php; (10) id parameter to cvote.php; and (11) commentid parameter to edit.php.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.1% — more likely to be exploited than 81% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2009-08-26
Last modified2026-06-16

Affected (1)

VendorProduct
pliggpligg cms

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD