CVE-2008-3573
Pligg 9.9.5 - Info Disclosure
Title source: llmDescription
The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) within the URL in the SRC attribute of an IMG element, which allows remote attackers to pass the CAPTCHA test via a calculation that combines this value with the current date and the HTTP User-Agent string.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Micheal Brooks · phpwebappsphp
https://www.exploit-db.com/exploits/32142
Scores
EPSS
0.0232
EPSS Percentile
84.9%
Details
CWE
CWE-189
CWE-264
Status
published
Products (2)
php-nuke/php-nuke
8.1
pligg/pligg
9.9.5
Published
Aug 10, 2008
Tracked Since
Feb 18, 2026