5

CVE-2007-4282

The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SerendipitySerendipity Version1.1.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.59% 0.725
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://blog.drinsama.de/erich/en/security/2007080801-security-issue-in-serendipity.html
http://blog.s9y.org/archives/178-Serendipity-1.1.4-released%2C-security-bug-in-entryproperties-plugin.html
http://osvdb.org/36534
http://secunia.com/advisories/26347
Vendor Advisory
http://sourceforge.net/forum/forum.php?forum_id=722867
Patch
http://sourceforge.net/project/shownotes.php?group_id=75065&release_id=530716
http://www.securityfocus.com/bid/25235
https://exchange.xforce.ibmcloud.com/vulnerabilities/35868