S9Y Serendipity 'include/functions_config.inc.php' HTML Injection Vulnerability
BID:42837
Info
S9Y Serendipity 'include/functions_config.inc.php' HTML Injection Vulnerability
| Bugtraq ID: | 42837 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 30 2010 12:00AM |
| Updated: | Aug 30 2010 12:00AM |
| Credit: | High-Tech Bridge SA |
| Vulnerable: |
S9Y Serendipity 1.5.3 S9Y Serendipity 1.5.2 S9Y Serendipity 1.3.1 S9Y Serendipity 1.2.1 S9Y Serendipity 1.1.4 S9Y Serendipity 1.1.3 S9Y Serendipity 1.1.1 S9Y Serendipity 1.0.4 S9Y Serendipity 1.0.3 S9Y Serendipity 0.9.1 S9Y Serendipity 0.8.2 S9Y Serendipity 0.8.1 S9Y Serendipity 0.8 -beta6 Snapshot S9Y Serendipity 0.8 -beta6 S9Y Serendipity 0.8 -beta5 S9Y Serendipity 0.8 S9Y Serendipity 0.7.1 S9Y Serendipity 0.7 beta3 S9Y Serendipity 0.7 beta1 S9Y Serendipity 0.7 -rc1 S9Y Serendipity 0.7 -beta4 S9Y Serendipity 0.7 -beta2 S9Y Serendipity 0.7 S9Y Serendipity 0.6 -rc2 S9Y Serendipity 0.6 -rc1 S9Y Serendipity 0.6 -pl3 S9Y Serendipity 0.6 -pl2 S9Y Serendipity 0.6 -pl1 S9Y Serendipity 0.6 S9Y Serendipity 0.5 -pl1 S9Y Serendipity 0.5 S9Y Serendipity 0.4 S9Y Serendipity 0.3 S9Y Serendipity 1.4 S9Y Serendipity 1.3-beta1 S9Y Serendipity 1.3 S9Y Serendipity 1.2-beta5 S9Y Serendipity 1.2 S9Y Serendipity 1.0.beta 3 S9Y Serendipity 1.0.beta 2 |
| Not Vulnerable: | |
Discussion
S9Y Serendipity 'include/functions_config.inc.php' HTML Injection Vulnerability
Serendipity is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, steal cookie-based authentication credentials, or control how the site is rendered to the user; other attacks are also possible.
Versions prior to Serendipity 1.5.4 are vulnerable.
Serendipity is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting this issue may allow an attacker to execute HTML and script code in the context of the affected site, steal cookie-based authentication credentials, or control how the site is rendered to the user; other attacks are also possible.
Versions prior to Serendipity 1.5.4 are vulnerable.
Exploit / POC
S9Y Serendipity 'include/functions_config.inc.php' HTML Injection Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
S9Y Serendipity 'include/functions_config.inc.php' HTML Injection Vulnerability
Solution:
The vendor released updates. Please see the references of more information.
Solution:
The vendor released updates. Please see the references of more information.
References
S9Y Serendipity 'include/functions_config.inc.php' HTML Injection Vulnerability
References:
References:
- Serendipity 'Remember Me' HTML Injection (High-Tech Bridge SA)
- Serendipity 1.5.4 released (S9y)
- Serendipity Homepage (S9Y)