FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-03-28 15:43:32 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
bec38383-e6cb-11de-bdd4-000c2930e89bpligg -- Cross-Site Scripting and Cross-Site Request Forgery

secunia reports:

Russ McRee has discovered some vulnerabilities in Pligg, which can be exploited by malicious people to conduct cross-site scripting and request forgery attacks.

Input passed via the "Referer" HTTP header to various scripts (e.g. admin/admin_config.php, admin/admin_modules.php, delete.php, editlink.php, submit.php, submit_groups.php, user_add_remove_links.php, and user_settings.php) is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to e.g. create an arbitrary user with administrative privileges if a logged-in administrative user visits a malicious web site.


Discovery 2009-12-02
Entry 2009-12-12
Modified 2010-05-02
pligg
< 1.0.3b

CVE-2009-4786
CVE-2009-4787
CVE-2009-4788
http://secunia.com/advisories/37349/
http://www.pligg.com/blog/775/pligg-cms-1-0-3-release/
c290f093-c89e-11e6-821e-68f7288bdf41Pligg CMS -- XSS Vulnerability

Netsparker reports:

Proof of Concept URL for XSS in Pligg CMS:

Page: groups.php

Parameter Name: keyword

Parameter Type: GET

Attack Pattern: http://example.com/pligg-cms-2.0.2/groups.php?view=search&keyword='+alert(0x000D82)+'

For more information on cross-site scripting vulnerabilities read the article Cross-site Scripting (XSS).


Discovery 2015-05-13
Entry 2016-12-22
pligg
le 2.0.2,1

https://www.netsparker.com/web-applications-advisories/ns-15-011-xss-vulnerability-identified-in-pligg-cms/