4.3
CVSSv2

CVE-2008-1476

Published: 24/03/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) prior to 1.3 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors related to received trackbacks.

Vulnerable Product Search on Vulmon Subscribe to Product

serendipity serendipity 0.7

serendipity serendipity 0.7.1

serendipity serendipity 0.9

serendipity serendipity 0.9.1

serendipity serendipity 1.0

serendipity serendipity 1.1.2

serendipity serendipity 1.1.3

serendipity serendipity 0.8

serendipity serendipity 0.8.1

serendipity serendipity 1.0.1

serendipity serendipity 1.0.2

serendipity serendipity 1.1.4

serendipity serendipity 1.2

serendipity serendipity 0.5_pl1

serendipity serendipity 0.6_pl3

serendipity serendipity 0.3

serendipity serendipity 0.4

serendipity serendipity 0.8.2

serendipity serendipity 0.8.3

serendipity serendipity 1.0.3

serendipity serendipity 1.0.4

serendipity serendipity

serendipity serendipity 0.8.4

serendipity serendipity 0.8.5

serendipity serendipity 1.1

serendipity serendipity 1.1.1

Vendor Advisories

Peter Hüwe and Hanno Böck discovered that Serendipity, a weblog manager, did not properly sanitise input to several scripts which allowed cross site scripting The old stable distribution (sarge) does not contain a serendipity package For the stable distribution (etch), this problem has been fixed in version 104-1+etch1 For the unstable distr ...