CVE-2009-4788: Input Validation
Published Apr 21, 2010
·Updated
Multiple open redirect vulnerabilities in Pligg 1.0.2 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the (1) return parameter to pligg/login.php and the (2) HTTP Referer header to usersettings.php.
Affected Software
14 affected components
Pligg Pligg CMS<=1.0.2
Pligg Pligg CMS=1.0.0-rc3
Pligg Pligg CMS=1.0.1
Pligg Pligg CMS=9.5
Pligg Pligg CMS=1.0.0-rc2
Pligg Pligg CMS=1.0.0
Pligg Pligg CMS=9.9.5
Pligg Pligg CMS=9.9.0-beta
Pligg Pligg CMS=9.9
Pligg Pligg CMS=9.9.5-beta
Pligg Pligg CMS=1.0.0-rc1
Pligg Pligg CMS=1.0.0-rc5
Pligg Pligg CMS=9.9.0
Pligg Pligg CMS=1.0.0-rc4
Remediation
Patch Available
Event History
Apr 21, 2010
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4788?
CVE-2009-4788 is classified as a critical vulnerability that allows for open redirects.
2
How do I fix CVE-2009-4788?
To fix CVE-2009-4788, upgrade to Pligg CMS version 1.0.3 or later.
3
What causes CVE-2009-4788?
CVE-2009-4788 is caused by multiple open redirect vulnerabilities in Pligg CMS.
4
Which versions of Pligg CMS are affected by CVE-2009-4788?
Pligg CMS versions 1.0.2 and earlier are affected by CVE-2009-4788.
5
What impact can CVE-2009-4788 have on users?
CVE-2009-4788 can lead to phishing attacks by redirecting users to arbitrary websites.