CVE-2008-7090: Path Traversal
Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .. (dot dot) in the $tburl variable in trackback.php, or (2) include arbitrary files via a .. (dot dot) in the template parameter to settemplate.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7090?
CVE-2008-7090 is classified as a high severity vulnerability due to its potential for directory traversal attacks.
How do I fix CVE-2008-7090?
To fix CVE-2008-7090, upgrade Pligg CMS to version 9.9.1 or later where this vulnerability has been addressed.
What types of attacks can exploit CVE-2008-7090?
CVE-2008-7090 can be exploited to perform arbitrary file inclusion or reveal the existence of sensitive files.
Which versions of Pligg CMS are affected by CVE-2008-7090?
Pligg CMS versions up to 9.9 and specifically version 9.5 are affected by CVE-2008-7090.
Is CVE-2008-7090 a widely exploited vulnerability?
While not one of the most commonly exploited vulnerabilities, CVE-2008-7090 poses significant risk to unpatched systems.