SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2008-1774.
📦
pligg_cms
Vendor: pligg
Actively Exploited
0
CISA KEV List
PoC / Exploits
13
Code Available
Total RCEs
1
Remote Access
Total CVEs
753
Total Indexed
Avg. EPSS
1.19%
Exploit Prob.
Security Vulnerability Index
Page 5 / 76
7.5
CVSS
CVE-2008-3366
Exploit Found
Severity: HIGH
7.5
CVSS
CVE-2008-1774
Exploit Found
SQL injection vulnerability in editlink.php in Pligg 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Severity: HIGH
7.5
CVSS
CVE-2007-5579
Exploit Found
login.php in Pligg CMS 9.5 uses a guessable confirmation code when resetting a forgotten password, which allows remote attackers with knowledge of a username to reset that user's password by calculating the confirmationcode parameter.
Severity: HIGH