Vulnerability Details CVE-2009-4788
Multiple open redirect vulnerabilities in Pligg 1.0.2 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the (1) return parameter to pligg/login.php and the (2) HTTP Referer header to user_settings.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.7%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2009-4788
-
cpe:2.3:a:pligg:pligg_cms:1.0.0
-
cpe:2.3:a:pligg:pligg_cms:1.0.1
-
cpe:2.3:a:pligg:pligg_cms:1.0.2
-
cpe:2.3:a:pligg:pligg_cms:9.5
-
cpe:2.3:a:pligg:pligg_cms:9.9
-
cpe:2.3:a:pligg:pligg_cms:9.9.0
-
cpe:2.3:a:pligg:pligg_cms:9.9.5