7.5
CVSSv2

CVE-2011-1134

Published: 05/11/2019 Updated: 08/11/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package prior to 1.5.5, allows remote malicious users to execute arbitrary code in the image manager.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

s9y serendipity

Vendor Advisories

Debian Bug report logs - #611661 Bundled plugins using Xinha allow malicious file uploads Package: serendipity; Maintainer for serendipity is (unknown); Reported by: "Daniel E Markle" <dmarkle@ashtechnet> Date: Mon, 31 Jan 2011 18:45:01 UTC Severity: grave Tags: security Found in version serendipity/153-2 Fixed in ver ...