First published: Wed Aug 26 2009(Updated: )
Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action to user.php and other unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pligg CMS | <=9.9.0 | |
Pligg CMS | =9.5 | |
Pligg CMS | =9.9.0-beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-7089 is a high severity cross-site scripting vulnerability that can allow attackers to inject malicious scripts.
To fix CVE-2008-7089, you should update Pligg CMS to version 9.9.1 or later, which addresses this vulnerability.
CVE-2008-7089 affects Pligg CMS versions up to and including 9.9.0, including 9.5 and the beta version 9.9.0-beta.
Exploitation of CVE-2008-7089 may lead to data theft, session hijacking, and the defacement of web pages.
Yes, CVE-2008-7089 can be exploited remotely by attackers to execute arbitrary web scripts in the context of the user's browser.