S9Y Serendipity 'Real Name' Field HTML Injection Vulnerability
BID:28003
Info
S9Y Serendipity 'Real Name' Field HTML Injection Vulnerability
| Bugtraq ID: | 28003 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0124 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2008 12:00AM |
| Updated: | Mar 24 2008 11:30PM |
| Credit: | Hanno Boeck is credited with the discovery of this vulnerability. |
| Vulnerable: |
S9Y Serendipity 1.2.1 S9Y Serendipity 1.1.4 S9Y Serendipity 1.1.3 S9Y Serendipity 1.1.1 S9Y Serendipity 1.0.4 S9Y Serendipity 1.0.3 S9Y Serendipity 0.9.1 S9Y Serendipity 0.8.2 S9Y Serendipity 0.8.1 S9Y Serendipity 0.8 -beta6 Snapshot S9Y Serendipity 0.8 -beta6 S9Y Serendipity 0.8 -beta5 S9Y Serendipity 0.8 S9Y Serendipity 0.7.1 S9Y Serendipity 0.7 beta3 S9Y Serendipity 0.7 beta1 S9Y Serendipity 0.7 -rc1 S9Y Serendipity 0.7 -beta4 S9Y Serendipity 0.7 -beta2 S9Y Serendipity 0.7 S9Y Serendipity 0.6 -rc2 S9Y Serendipity 0.6 -rc1 S9Y Serendipity 0.6 -pl3 S9Y Serendipity 0.6 -pl2 S9Y Serendipity 0.6 -pl1 S9Y Serendipity 0.6 S9Y Serendipity 0.5 -pl1 S9Y Serendipity 0.5 S9Y Serendipity 0.4 S9Y Serendipity 0.3 S9Y Serendipity 1.2-beta5 S9Y Serendipity 1.2 S9Y Serendipity 1.0.beta 3 S9Y Serendipity 1.0.beta 2 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
S9Y Serendipity 1.3-beta1 |
Discussion
S9Y Serendipity 'Real Name' Field HTML Injection Vulnerability
Serendipity is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to Serendipity 1.3-beta1 are vulnerable.
Serendipity is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to Serendipity 1.3-beta1 are vulnerable.
Exploit / POC
S9Y Serendipity 'Real Name' Field HTML Injection Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
S9Y Serendipity 'Real Name' Field HTML Injection Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Solution:
The vendor released updates to address this issue. Please see the references for more information.
References
S9Y Serendipity 'Real Name' Field HTML Injection Vulnerability
References:
References: