CVE-2009-4788
Last modified
CVE-2009-4788 is a vulnerability of currently unknown severity. Multiple open redirect vulnerabilities in Pligg 1.0.2 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the (1) return parameter to pligg/login.php and the (2) HTTP Referer header to user_settings.php.. EPSS estimates a 1.04% chance of exploitation in the next 30 days.
Description
Multiple open redirect vulnerabilities in Pligg 1.0.2 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the (1) return parameter to pligg/login.php and the (2) HTTP Referer header to user_settings.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pligg | Pligg Cms | <= 1.0.2 |
| Pligg | Pligg Cms | 1.0.0 |
| Pligg | Pligg Cms | 1.0.1 |
| Pligg | Pligg Cms | 9.5 |
| Pligg | Pligg Cms | 9.9 |
| Pligg | Pligg Cms | 9.9.0 |
| Pligg | Pligg Cms | 9.9.5 |
References
- http://secunia.com/advisories/37349Vendor Advisory
- http://secunia.com/advisories/37349Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4788?
How severe is CVE-2009-4788?
How do I fix CVE-2009-4788?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-4782Multiple cross-site scripting (XSS) vulnerabilities in Theet…
- CVE-2009-4783Multiple SQL injection vulnerabilities in Theeta CMS, possib…
- CVE-2009-4784SQL injection vulnerability in the Joaktree (com_joaktree) c…
- CVE-2009-4785SQL injection vulnerability in the Quick News (com_quicknews…
- CVE-2009-4786Multiple cross-site scripting (XSS) vulnerabilities in Pligg…
- CVE-2009-4787Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2009-4789Multiple PHP remote file inclusion vulnerabilities in the Mo…
- CVE-2009-4790Multiple directory traversal vulnerabilities in Sysax Multi …
- CVE-2009-4791Multiple SQL injection vulnerabilities in Family Connections…
- CVE-2009-4792SQL injection vulnerability in includes/content/member_conte…
- CVE-2009-4793Unrestricted file upload vulnerability in adminpanel/scripts…
- CVE-2009-4794Multiple SQL injection vulnerabilities in Community CMS 0.5 …
Are you affected by CVE-2009-4788?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
