CVE-2007-6205
- EPSS 0.9%
- Veröffentlicht 11.12.2007 20:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the remote RSS sidebar plugin (serendipity_plugin_remoterss) in S9Y Serendipity before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via a link in an RSS feed.
CVE-2006-6242
- EPSS 4.41%
- Veröffentlicht 03.12.2006 19:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a .. (dot dot) sequence in the serendipity[charset] parameter in (1) include/lang.inc.php; or to plugins...
CVE-2006-2495
- EPSS 0.72%
- Veröffentlicht 20.05.2006 03:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag.
CVE-2006-1910
- EPSS 0.76%
- Veröffentlicht 20.04.2006 18:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and later executed. NOTE: the provenance of this information is unknown; the details are obtained solely fr...
CVE-2005-3129
- EPSS 1.68%
- Veröffentlicht 04.10.2005 22:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin.php.
CVE-2005-1713
- EPSS 0.35%
- Veröffentlicht 24.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.
- EPSS 0.38%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."
CVE-2005-1451
- EPSS 0.72%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.
CVE-2005-1450
- EPSS 0.53%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unknown vulnerability in "the function used to validate path-names for uploading media" in Serendipity before 0.8 has unknown impact.
- EPSS 0.38%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.