7.5
CVSSv2

CVE-2008-5739

Published: 26/12/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote malicious users to execute arbitrary SQL commands via the url parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

pligg pligg cms 9.9.5

Exploits

#!/usr/bin/perl =about Pligg 995 Beta Perl exploit AUTHOR discovered & written by Ams ax330d [doggy] gmail [dot] com VULN DESCRIPTION: Vulnerability hides in 'evb/check_urlphp' unfiltered $_GET['url'] parameter Actually, it has filtration Filtration strips tags and converts html special chars , but it is not enough, becaus ...