PT-2008-2969 · S9Y · Serendipity

Hanno Boeck

·

Publicado

2008-04-23

·

Atualizado

2018-10-11

·

CVE-2008-1386

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Serendipity (S9Y) version 1.3
Description The issue allows remote attackers to inject arbitrary web script or HTML via unspecified path fields or the database host field, potentially leading to cross-site scripting (XSS) attacks. The timing window for exploitation of this issue might be limited.
Recommendations For Serendipity (S9Y) version 1.3, consider updating to a newer version that addresses the cross-site scripting vulnerabilities, specifically focusing on securing the installer and input validation for path fields and the database host field. As a temporary workaround, restrict access to the installer and ensure proper input validation to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1386

Produtos afetados

Serendipity