CVE-2009-4786 Information
Feb 14, 2021
cve
Description
Multiple cross-site scripting (XSS) vulnerabilities in Pligg before 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to (1) admin/admin_config.php (2) admin/admin_modules.php (3) delete.php (4) editlink.php (5) submit.php (6) submit_groups.php (7) user_add_remove_links.php and (8) user_settings.php.
Reference
http://holisticinfosec.org/content/view/130/45/ http://secunia.com/advisories/37349 http://www.pligg.com/blog/775/pligg-cms-1-0-3-release/
Share on: