vendor:
Plogger
by:
killall-9@mail.com
8,8
CVSS
HIGH
Reflected XSS, Stored XSS, CSRF
79, 79, 352
CWE
Product Name: Plogger
Affected Version From: 1.0 (RC1)
Affected Version To: 1.0 (RC1)
Patch Exists: NO
Related CWE: N/A
CPE: plogger:plogger
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Virtualbox (debian) and Apache
2014
Multiply vulnerabilites in plogger 1.0 (RC1)
The Plogger 1.0 (RC1) is vulnerable to Reflected XSS, Stored XSS and CSRF. Reflected XSS can be exploited by sending a malicious URL to the victim. Stored XSS can be exploited by sending a malicious payload in the description field. CSRF can be exploited by sending a malicious HTML page to the victim.
Mitigation:
Input validation, Input validation, CSRF token