S9y

Serendipity

62 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 5.49%
  • Veröffentlicht 04.10.2005 22:02:00
  • Zuletzt bearbeitet 16.06.2026 22:16:18

Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin.php.

  • EPSS 1.21%
  • Veröffentlicht 24.05.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:13:33

Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.

  • EPSS 1.41%
  • Veröffentlicht 03.05.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:13:04

Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."

  • EPSS 1.57%
  • Veröffentlicht 03.05.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:13:04

The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.

  • EPSS 1.32%
  • Veröffentlicht 03.05.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:13:04

Unknown vulnerability in "the function used to validate path-names for uploading media" in Serendipity before 0.8 has unknown impact.

  • EPSS 1.41%
  • Veröffentlicht 03.05.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:13:03

Unknown vulnerability in serendipity_config_local.inc.php for Serendipity before 0.8 has unknown impact.

  • EPSS 1.34%
  • Veröffentlicht 03.05.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:13:03

Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

Exploit
  • EPSS 1.75%
  • Veröffentlicht 13.04.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:12:29

SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.

  • EPSS 1.33%
  • Veröffentlicht 31.12.2004 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:09:49

Cross-site scripting (XSS) vulnerability in compat.php in Serendipity before 0.7.1 allows remote attackers to inject arbitrary web script or HTML via the searchTerm variable.

Exploit
  • EPSS 4.11%
  • Veröffentlicht 31.12.2004 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:09:07

SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.php or (2) comment.php.