CVE-2008-7090
Pligg CMS < 9.9 - Path Traversal via Trackback URL or Template Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7090. PoCs published by GulfTech Security.
AI-analyzed exploit summary This is a detailed advisory describing multiple vulnerabilities in Pligg CMS, including SQL injection, XSS, and arbitrary file access. It provides technical explanations and exploitation examples but does not include executable exploit code.
Description
Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .. (dot dot) in the $tb_url variable in trackback.php, or (2) include arbitrary files via a .. (dot dot) in the template parameter to settemplate.php.
Exploits (1)
This is a detailed advisory describing multiple vulnerabilities in Pligg CMS, including SQL injection, XSS, and arbitrary file access. It provides technical explanations and exploitation examples but does not include executable exploit code.