CVE-2008-7089: XSS
Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action to user.php and other unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7089?
CVE-2008-7089 is a high severity cross-site scripting vulnerability that can allow attackers to inject malicious scripts.
How do I fix CVE-2008-7089?
To fix CVE-2008-7089, you should update Pligg CMS to version 9.9.1 or later, which addresses this vulnerability.
What versions of Pligg are affected by CVE-2008-7089?
CVE-2008-7089 affects Pligg CMS versions up to and including 9.9.0, including 9.5 and the beta version 9.9.0-beta.
What are the possible consequences of CVE-2008-7089?
Exploitation of CVE-2008-7089 may lead to data theft, session hijacking, and the defacement of web pages.
Can CVE-2008-7089 be exploited remotely?
Yes, CVE-2008-7089 can be exploited remotely by attackers to execute arbitrary web scripts in the context of the user's browser.