XSS vulnerability on comment?

Register an Account
Reply
 
Thread Tools Display Modes
  #1 (permalink)  
Old 09-24-2008, 12:22 AM
New Pligger
Pligg Version: 9.9.5
 
Join Date: Sep 2008
Posts: 5
I upgraded mysite to 9.9.5 a few days ago,and still the spam comes.
When I went to admin_comments.php.the page automatic redirect to a spam site.
I check the html code of admin_comments.php and found that spammer insert a script(http://bigbigsavings.info/rd.js) in the comment.

Is there any way to solve this problem?
Reply With Quote
  #2 (permalink)  
Old 09-26-2008, 03:09 AM
New Pligger
Pligg Version: 9.9.5
 
Join Date: Sep 2008
Posts: 5
I post the admin_comments.php html code as attachment.

when you open it. it will automatic redirect to spam site.

please tell me whether you have fix that and how can I find the patch.thanks.
Attached Files
File Type: html admin_comments_xss.html (27.5 KB, 267 views)
Reply With Quote
  #3 (permalink)  
Old 09-26-2008, 06:01 AM
New Pligger
Pligg Version: Pligg Beta 9.8.2
Pligg Template: Default
 
Join Date: Jan 2008
Posts: 2
Hi, I have the same problem, please help.....


Quote:
Originally Posted by wwwawww View Post
I post the admin_comments.php html code as attachment.

when you open it. it will automatic redirect to spam site.

please tell me whether you have fix that and how can I find the patch.thanks.
Reply With Quote
  #4 (permalink)  
Old 09-27-2008, 01:23 PM
New Pligger
Pligg Version: 9.8
Pligg Template: .
 
Join Date: Jan 2008
Posts: 5
+1 I have the same problem!
Reply With Quote
  #5 (permalink)  
Old 09-27-2008, 02:54 PM
New Pligger
 
Join Date: Jul 2008
Posts: 18
Pligg <= 9.9.0 (XSS/LFI/SQL) Multiple Remote Vulnerabilities

you guys might wanna check that our, our PLIGG scripts have lots of vulerabilites =[ ugh. not cool
Reply With Quote
  #6 (permalink)  
Old 09-27-2008, 06:29 PM
New Pligger
 
Join Date: Aug 2008
Posts: 19
Solution:
The Pligg developers are aware of the issues mentioned in this advisory
and an updated version of Pligg should be available from their website.
All users are encouraged to upgrade their Pligg installations as soon
as possible.

Make sure you guys are using version 9.9.5 not 9.9.0
Reply With Quote
  #7 (permalink)  
Old 09-28-2008, 05:18 AM
New Pligger
Pligg Version: 9.9.5
 
Join Date: Sep 2008
Posts: 5
Of course I use 9.9.5.
but the problem remains
Reply With Quote
  #8 (permalink)  
Old 09-28-2008, 05:19 AM
New Pligger
Pligg Version: 9.9.5
 
Join Date: Sep 2008
Posts: 5
Quote:
Originally Posted by iamneat1 View Post
Pligg <= 9.9.0 (XSS/LFI/SQL) Multiple Remote Vulnerabilities

you guys might wanna check that our, our PLIGG scripts have lots of vulerabilites =[ ugh. not cool
and I dont think it's the same issue
Reply With Quote
  #9 (permalink)  
Old 09-28-2008, 06:15 AM
New Pligger
 
Join Date: Jan 2007
Posts: 15
same problem in this file
Reply With Quote
  #10 (permalink)  
Old 10-05-2008, 03:02 AM
New Pligger
 
Join Date: May 2007
Posts: 19
I am using Pligg Version: 9.9.5, have same problem 2.....
Reply With Quote
Reply

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
Use "disqus" in comment lochoe Questions and Comments 24 06-19-2011 02:29 PM
Editing a reply to a comment? bbrian017 Questions and Comments 0 01-10-2008 05:30 PM
A proposal for a more robust way of comment deletion. sefs Questions and Comments 0 10-12-2007 05:30 PM
Comment Count Update Simon Questions and Comments 4 06-01-2007 10:45 PM


Pligg Modules and Pligg Templates from Pligg Pro Find support on the Pligg CMS Forum - 24 hours a day! Make a donation to support Pligg CMS development