6.8
CVSSv2

CVE-2015-6655

Published: 31/08/2015 Updated: 22/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote malicious users to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php.

Vulnerable Product Search on Vulmon Subscribe to Product

pligg pligg cms 2.0.2

Exploits

<!-- # Exploit Title: Pligg CMS CSRF Add Admin Exploit # Google Dork: intext:"Made wtih Pligg CMS" # Date: 2015/8/20 # Exploit Author: Arash Khazaei # Vendor Homepage: pliggcom # Software Link: githubcom/Pligg/pligg-cms/releases/download/202/202zip # Version: 202 # Tested on: Kali , Iceweasel Browser # CVE : CVE-2015-6655 ...
Pligg CMS version 202 suffers from a cross site request forgery vulnerability ...