about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , S9Y Serendipity HTML Injection and Cross-Site Scripting Vulnerabilities


Title S9Y Serendipity HTML Injection and Cross-Site Scripting Vulnerabilities
Published 2008-04-22-12:00AM
Updated 2008-04-22-09:17PM
Class Input Validation Error
CVE   CVE-2008-1385 E-2008-1386
Remote  Yes
Local  No
Credit  Hanno Boeck
Vulnerable  S9Y Serendipity 1.3
Not Vulnerable  S9Y Serendipity 1.3.1
Code  Attackers can exploit these issues through a browser. To exploit the cross-site scripting issue, attackers must entice an unsuspecting user to follow a malicious URI.The following proof of concept is available for the referrer issue:wget --referer='http://<hr onMouseOver="alert(7)">' http://someblog.com/
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Fri, 18 Dec 2009 15:03:58 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Www.Xnxxco www.mqdm.n intl jc @ Web Camera Video+sex+ avizzon www.chengs XDOMain.bl epmap news for c Free+sex+v www.lmbbs. maxcpm.inf BLUEFILM.C 3.9 strings guest book news for c helm messaging php-nuke 2 Www.sexzoo maxcpm.inf member8.ta news for c www.petard 200 /compo vmvmn news for c indiangirl t467t www.zhmf51 proftp exp fuat IP Spoofin mrtg www.it197. bill gates javacript: serials wi Nagma sex KAJAL photo teen 200 /compo dbal.php Crack Data www.sf123. PHP Photo www.taobao Tomcat