|
Pligg 1.0.2 contains a flaw that allows a remote cross site redirection attack. This flaw exists because the application does not validate the "return" parameter upon submission to the user_settings.php script. This could allow a user to create a specially crafted URL, that if clicked, would redirect a victim from the intended legitimate web site to an arbitrary web site of the attacker's choosing. This could be leveraged to direct a user to a web page containing attacks that target client side software such as a web browser or document rendering programs.
|