Vulnerabilities > CVE-2007-4282 - Unspecified vulnerability in Serendipity 1.1.3
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://blog.drinsama.de/erich/en/security/2007080801-security-issue-in-serendipity.html
- http://sourceforge.net/forum/forum.php?forum_id=722867
- http://sourceforge.net/project/shownotes.php?group_id=75065&release_id=530716
- http://secunia.com/advisories/26347
- http://www.securityfocus.com/bid/25235
- http://osvdb.org/36534
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35868
- http://blog.s9y.org/archives/178-Serendipity-1.1.4-released%2C-security-bug-in-entryproperties-plugin.html