Unrated severityNVD Advisory· Published Apr 21, 2010· Updated Apr 29, 2026
CVE-2009-4786
CVE-2009-4786
Description
Multiple cross-site scripting (XSS) vulnerabilities in Pligg before 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to (1) admin/admin_config.php, (2) admin/admin_modules.php, (3) delete.php, (4) editlink.php, (5) submit.php, (6) submit_groups.php, (7) user_add_remove_links.php, and (8) user_settings.php.
Affected products
14cpe:2.3:a:pligg:pligg_cms:*:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:pligg:pligg_cms:*:*:*:*:*:*:*:*range: <=1.0.2
- cpe:2.3:a:pligg:pligg_cms:1.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:pligg:pligg_cms:1.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:pligg:pligg_cms:1.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:pligg:pligg_cms:1.0.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:pligg:pligg_cms:1.0.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:pligg:pligg_cms:1.0.0:rc5:*:*:*:*:*:*
- cpe:2.3:a:pligg:pligg_cms:1.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:pligg:pligg_cms:9.5:*:*:*:*:*:*:*
- cpe:2.3:a:pligg:pligg_cms:9.9:*:*:*:*:*:*:*
- cpe:2.3:a:pligg:pligg_cms:9.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:pligg:pligg_cms:9.9.0:beta:*:*:*:*:*:*
- cpe:2.3:a:pligg:pligg_cms:9.9.5:*:*:*:*:*:*:*
- cpe:2.3:a:pligg:pligg_cms:9.9.5:beta:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.pligg.com/blog/775/pligg-cms-1-0-3-release/nvdPatchVendor Advisory
- secunia.com/advisories/37349nvdVendor Advisory
- holisticinfosec.org/content/view/130/45/nvd
News mentions
0No linked articles in our index yet.