- EPSS 0.28%
- Published 24.09.2011 00:55:03
- Last modified 11.04.2025 00:51:21
Serendipity 1.5.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by templates/newspaper/layout.php and certain other files.
CVE-2010-2957
- EPSS 0.29%
- Published 10.09.2010 18:00:02
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Serendipity before 1.5.4, when "Remember me" logins are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2010-1916
- EPSS 0.71%
- Published 12.05.2010 11:46:40
- Last modified 11.04.2025 00:51:21
The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers to bypass intended access restrictions and modify the configuration of arbitrary plugins via (1) craf...
- EPSS 2.11%
- Published 24.12.2009 16:30:00
- Last modified 09.04.2025 00:30:58
Unrestricted file upload vulnerability in Serendipity before 1.5 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the ...
CVE-2008-1386
- EPSS 0.5%
- Published 23.04.2008 13:05:00
- Last modified 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in the installer in Serendipity (S9Y) 1.3 allow remote attackers to inject arbitrary web script or HTML via (1) unspecified path fields or (2) the database host field. NOTE: the timing window for e...
CVE-2008-1385
- EPSS 6.74%
- Published 23.04.2008 13:05:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.
CVE-2008-0124
- EPSS 0.65%
- Published 28.02.2008 20:44:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3-beta1 allows remote authenticated users to inject arbitrary web script or HTML via (1) the "Real name" field in Personal Settings, which is presented to readers of articles; or ...
CVE-2007-6205
- EPSS 0.59%
- Published 11.12.2007 20:46:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the remote RSS sidebar plugin (serendipity_plugin_remoterss) in S9Y Serendipity before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via a link in an RSS feed.
CVE-2006-6242
- EPSS 4.41%
- Published 03.12.2006 19:28:00
- Last modified 09.04.2025 00:30:58
Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a .. (dot dot) sequence in the serendipity[charset] parameter in (1) include/lang.inc.php; or to plugins...
CVE-2006-2495
- EPSS 0.72%
- Published 20.05.2006 03:02:00
- Last modified 03.04.2025 01:03:51
Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag.