Vulnerabilities > Serendipity
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-03-24 | CVE-2008-1476 | Cross-Site Scripting vulnerability in Serendipity Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to received trackbacks. | 4.3 |
2007-12-17 | CVE-2007-6390 | Cross-Site Request Forgery (CSRF) vulnerability in Serendipity Cross-site request forgery (CSRF) vulnerability in the mycalendar plugin before 0.13 for Serendipity allows remote attackers to perform actions as blog administrators, which can be leveraged to conduct cross-site scripting (XSS) attacks on the blog page. | 4.3 |
2007-03-07 | CVE-2007-1326 | SQL-Injection vulnerability in Serendipity 1.1.1 SQL injection vulnerability in index.php in Serendipity 1.1.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[multiCat][] parameter. | 7.5 |
2006-10-25 | CVE-2006-5499 | Cross-Site Scripting vulnerability in Serendipity Administration Page Multiple cross-site scripting (XSS) vulnerabilities in Serendipity (s9y) 1.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in the media manager administration page. network serendipity | 6.8 |