4.3
CVSSv2

CVE-2007-6205

Published: 11/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the remote RSS sidebar plugin (serendipity_plugin_remoterss) in S9Y Serendipity prior to 1.2.1 allows remote malicious users to inject arbitrary web script or HTML via a link in an RSS feed.

Vulnerable Product Search on Vulmon Subscribe to Product

s9y serendipity 0.4

s9y serendipity 0.5

s9y serendipity 0.7

s9y serendipity 0.7.1

s9y serendipity 0.8.1

s9y serendipity 0.8.2

s9y serendipity 0.8_beta6

s9y serendipity 0.9

s9y serendipity 1.1.3

s9y serendipity 1.1.4

s9y serendipity 0.6_pl1

s9y serendipity 0.6_pl2

s9y serendipity 0.7_beta3

s9y serendipity 0.7_beta4

s9y serendipity 0.8.5

s9y serendipity 0.8_beta_5

s9y serendipity 1.0.4

s9y serendipity 1.0_beta1

s9y serendipity 0.5_pl1

s9y serendipity 0.6

s9y serendipity 0.7_beta1

s9y serendipity 0.7_beta2

s9y serendipity 0.8.3

s9y serendipity 0.8.4

s9y serendipity 0.9.1

s9y serendipity 1.0.3

s9y serendipity 0.3

s9y serendipity 0.6_pl3

s9y serendipity 0.6_rc1

s9y serendipity 0.6_rc2

s9y serendipity 0.7_rc1

s9y serendipity 0.8

s9y serendipity 0.8_beta_6

s9y serendipity 0.8_beta5

s9y serendipity 1.0_beta2

s9y serendipity 1.0_beta3

s9y serendipity 1.1.1

Vendor Advisories

Peter Hüwe and Hanno Böck discovered that Serendipity, a weblog manager, did not properly sanitise input to several scripts which allowed cross site scripting The old stable distribution (sarge) does not contain a serendipity package For the stable distribution (etch), this problem has been fixed in version 104-1+etch1 For the unstable distr ...

Exploits

The Serendipity blog system contains a plugin to display the content of feeds in the sidebar (serendipity_plugin_remoterss) If an attacker can modify the RSS feed, it is possible to inject javascript code in the link part, because it is not correctly escaped Versions below 121 are affected ...