CVE-2009-4786: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Pligg before 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to (1) admin/adminconfig.php, (2) admin/adminmodules.php, (3) delete.php, (4) editlink.php, (5) submit.php, (6) submitgroups.php, (7) useraddremovelinks.php, and (8) usersettings.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4786?
CVE-2009-4786 has a medium severity level due to its cross-site scripting vulnerabilities that can allow remote attackers to execute arbitrary scripts.
How do I fix CVE-2009-4786?
To fix CVE-2009-4786, you should upgrade Pligg CMS to version 1.0.3 or later, which addresses these vulnerabilities.
Which versions of Pligg CMS are affected by CVE-2009-4786?
CVE-2009-4786 affects all Pligg CMS versions prior to 1.0.3, including versions like 1.0.0 through 1.0.2.
Can CVE-2009-4786 affect website security?
Yes, CVE-2009-4786 can significantly compromise website security by enabling attackers to inject malicious scripts through user input.
What are the potential impacts of CVE-2009-4786?
The potential impacts of CVE-2009-4786 include unauthorized access, data theft, and the manipulation of website content through cross-site scripting attacks.