CVE-2006-1910
- EPSS 0.76%
- Published 20.04.2006 18:06:00
- Last modified 03.04.2025 01:03:51
config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and later executed. NOTE: the provenance of this information is unknown; the details are obtained solely fr...
CVE-2005-3129
- EPSS 1.68%
- Published 04.10.2005 22:02:00
- Last modified 03.04.2025 01:03:51
Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin.php.
CVE-2005-1713
- EPSS 0.35%
- Published 24.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.
- EPSS 0.38%
- Published 03.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."
CVE-2005-1451
- EPSS 0.72%
- Published 03.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.
CVE-2005-1450
- EPSS 0.53%
- Published 03.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Unknown vulnerability in "the function used to validate path-names for uploading media" in Serendipity before 0.8 has unknown impact.
- EPSS 0.38%
- Published 03.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.
CVE-2005-1448
- EPSS 1.01%
- Published 03.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVE-2005-1134
- EPSS 2.26%
- Published 13.04.2005 04:00:00
- Last modified 03.04.2025 01:03:51
SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.
CVE-2004-2525
- EPSS 0.57%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in compat.php in Serendipity before 0.7.1 allows remote attackers to inject arbitrary web script or HTML via the searchTerm variable.