CVE-2008-7090 describes multiple directory traversal vulnerabilities in Pligg CMS versions 9.9 and earlier. These flaws allow remote attackers to either determine the existence of arbitrary files via the $tb_url variable in trackback.php or include arbitrary files through the template parameter in settemplate.php. With a CVSS score of 7.8 (High), the vulnerability is easily exploitable over the network with no authentication, potentially leading to complete confidentiality compromise. While not listed on the KEV catalog and showing no active exploitation or community discussion, an ExploitDB entry (EDB-6173) indicates the existence of proof-of-concept code for Local File Inclusion, alongside XSS and SQL Injection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.9CPE matchmatch criteria | cpe:2.3:a:pligg:pligg_cms:*:*:*:*:*:*:*:* | ||
9.5CPE matchmatch criteria | cpe:2.3:a:pligg:pligg_cms:9.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.