Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
s9y serendipity 2.0.5 vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2017-8101
There is CSRF in Serendipity 2.0.5, allowing malicious users to install any themes via a GET request.
S9y Serendipity 2.0.5
8.8
CVSSv3
CVE-2017-5609
SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via the cat parameter.
S9y Serendipity 2.0.5
8.8
CVSSv3
CVE-2017-5475
comment.php in Serendipity up to and including 2.0.5 allows CSRF in deleting any comments.
S9y Serendipity
8.8
CVSSv3
CVE-2017-5476
Serendipity up to and including 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin.
S9y Serendipity
8.6
CVSSv3
CVE-2016-9752
In Serendipity prior to 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) HTTP status code.
S9y Serendipity
5.4
CVSSv3
CVE-2016-9681
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity prior to 2.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a category or directory name.
S9y Serendipity
6.1
CVSSv3
CVE-2017-5474
Open redirect vulnerability in comment.php in Serendipity up to and including 2.0.5 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.
S9y Serendipity
9.8
CVSSv3
CVE-2016-10082
include/functions_installer.inc.php in Serendipity up to and including 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it fails to sanitize the dbType POST parameter before adding it to an include() call in the b...
S9y Serendipity
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-37316
firmware
CVE-2024-30078
CVE-2024-5995
remote code execution
logic flaw
CVE-2024-20693
CVE-2024-37315
CVE-2024-5464
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started