CVE-2008-7091

Pligg CMS < 9.9.0 - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-7091. PoCs published by GulfTech Security.

AI-analyzed exploit summary This exploit targets Pligg CMS versions up to 9.9, leveraging SQL injection to extract admin credentials and then injecting PHP code into a template file to achieve remote code execution. It provides an interactive shell upon successful exploitation.

Description

Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to vote.php, which is not properly handled in libs/link.php; (2) id parameter to trackback.php; (3) an unspecified parameter to submit.php; (4) requestTitle variable in a query to story.php; (5) requestID and (6) requestTitle variables in recommend.php; (7) categoryID parameter to cloud.php; (8) title parameter to out.php; (9) username parameter to login.php; (10) id parameter to cvote.php; and (11) commentid parameter to edit.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by GulfTech Security · perlwebappsphp
https://www.exploit-db.com/exploits/6172

This exploit targets Pligg CMS versions up to 9.9, leveraging SQL injection to extract admin credentials and then injecting PHP code into a template file to achieve remote code execution. It provides an interactive shell upon successful exploitation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Pligg CMS <= 9.9
No auth needed
Prerequisites: Target must be running Pligg CMS <= 9.9 · Network access to the target's web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/6173

This is a detailed advisory describing multiple vulnerabilities in Pligg CMS, including SQL injection, XSS, and arbitrary file access. It provides technical explanations and exploitation examples but does not include executable exploit code.

Classification
Writeup 100%
Attack Type
Sqli | Xss | Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Pligg CMS <= 9.9
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (15)

Core 15
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/50191
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44193
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/50198
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/50195
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/50193
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/494987/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/50194
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30458
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/50190
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/50192
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/50189
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/50196
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/50197
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6173

Scores

EPSS 0.0210
EPSS Percentile 79.3%

Details

CWE
CWE-89
Status published
Products (3)
pligg/pligg_cms 9.5
pligg/pligg_cms 9.9.0 beta
pligg/pligg_cms < 9.9.0
Published Aug 26, 2009
Tracked Since Feb 18, 2026