On Tuesday of this week we alerted Pligg based CMS users to a Remote SQL Injection Vulnerability that was present within the story.php. This issue is caused by an input validation error in the "story.php" script when processing the "id" parameter. The vulnerability could be exploited by malicious people to conduct SQL injection attacks and gain knowledge of sensitive information. Today evidence has arisen from James Bercegay of the GulfTech Security Research Team that would indicate that Pligg has many, many more security vulnerabilities from SQL attacks.
July 31st, 2008 | Pligg | Lincoln | 7 comments | ContinuedAll Posts Tagged With: "pligg security threat"
Pligg Beta 9.9.0 Remote SQL Injection Vulnerability Discovered
A new security vulnerability in Pligg V9.9.0 has been discovered at milw0rm.com, the exact type of security threat is that of a Remote SQL Injection in Pligg's story.php. The pligg team have been alerted to the vulnerability from a user post by edupin in the pligg forums here, the post however now seems to have been deleted. You can view a Google cached version of the original pligg post here or find it through a Google search here.
July 29th, 2008 | Pligg | Lincoln | 2 comments | Continued