CVE-2010-2957 Information

Description

Cross-site scripting (XSS) vulnerability in Serendipity before 1.5.4 when \Remember me\ logins are enabled allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Reference

http://blog.s9y.org/archives/223-Serendipity-1.5.4-released.html http://www.htbridge.ch/advisory/xss_vulnerability_in_serendipity.html http://www.openwall.com/lists/oss-security/2010/08/29/3 http://www.openwall.com/lists/oss-security/2010/08/31/5

Share on: