CVE-2008-1385
- EPSS 6.74%
- Veröffentlicht 23.04.2008 13:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.
CVE-2008-0124
- EPSS 0.74%
- Veröffentlicht 28.02.2008 20:44:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3-beta1 allows remote authenticated users to inject arbitrary web script or HTML via (1) the "Real name" field in Personal Settings, which is presented to readers of articles; or ...
CVE-2007-6205
- EPSS 0.66%
- Veröffentlicht 11.12.2007 20:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the remote RSS sidebar plugin (serendipity_plugin_remoterss) in S9Y Serendipity before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via a link in an RSS feed.
CVE-2006-6242
- EPSS 4.41%
- Veröffentlicht 03.12.2006 19:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include arbitrary local files via a .. (dot dot) sequence in the serendipity[charset] parameter in (1) include/lang.inc.php; or to plugins...
CVE-2006-2495
- EPSS 0.72%
- Veröffentlicht 20.05.2006 03:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Cross-site request forgery (CSRF) vulnerability in the Entry Manager in Serendipity before 1.0-beta3 allows remote attackers to perform unauthorized actions as a logged-in user via a link or IMG tag.
CVE-2006-1910
- EPSS 0.76%
- Veröffentlicht 20.04.2006 18:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
config.php in S9Y Serendipity 1.0 beta 2 allows remote attackers to inject arbitrary PHP code by editing values that are stored in config.php and later executed. NOTE: the provenance of this information is unknown; the details are obtained solely fr...
CVE-2005-3129
- EPSS 1.68%
- Veröffentlicht 04.10.2005 22:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin.php.
CVE-2005-1713
- EPSS 0.35%
- Veröffentlicht 24.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.
- EPSS 0.47%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."
CVE-2005-1451
- EPSS 0.72%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.