First published: Mon Aug 16 2010(Updated: )
Multiple SQL injection vulnerabilities in Pligg before 1.1.1 allow remote attackers to execute arbitrary SQL commands via the title parameter to (1) storyrss.php or (2) story.php.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pligg CMS | <=1.1.0 | |
Pligg CMS | =1.0.0-rc3 | |
Pligg CMS | =1.0.1 | |
Pligg CMS | =1.0.0-rc2 | |
Pligg CMS | =1.0.0 | |
Pligg CMS | =1.0.4 | |
Pligg CMS | =1.0.2 | |
Pligg CMS | =1.0.0-rc1 | |
Pligg CMS | =1.0.0-rc5 | |
Pligg CMS | =1.0.0-rc4 | |
Pligg CMS | =1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2577 is classified as a high-severity vulnerability due to its ability to allow remote attackers to execute arbitrary SQL commands.
To fix CVE-2010-2577, upgrade Pligg CMS to version 1.1.1 or later.
Versions of Pligg CMS prior to 1.1.1, including 1.0.0 through 1.0.4 and release candidates, are vulnerable to CVE-2010-2577.
CVE-2010-2577 can enable SQL injection attacks that may lead to unauthorized database access and manipulation.
Addressing CVE-2010-2577 is essential as failing to do so can result in serious data breaches and security incidents.