Vulnerabilities
Vulnerable Software
S9y:  >> Serendipity  >> 1.5.3  Security Vulnerabilities
SQL injection vulnerability in serendipity/serendipity_admin.php in Serendipity before 1.6.1 allows remote attackers to execute arbitrary SQL commands via the serendipity[plugin_to_conf] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF).
CVSS Score
7.5
EPSS Score
0.013
Published
2012-08-13
SQL injection vulnerability in include/functions_trackbacks.inc.php in Serendipity 1.6.2 allows remote attackers to execute arbitrary SQL commands via the url parameter to comment.php.
CVSS Score
7.5
EPSS Score
0.007
Published
2012-06-07
Cross-site scripting (XSS) vulnerability in Serendipity before 1.5.4, when "Remember me" logins are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
2.6
EPSS Score
0.003
Published
2010-09-10


Contact Us

Shodan ® - All rights reserved