Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.
Link | Tags |
---|---|
http://sourceforge.net/project/shownotes.php?release_id=328092 | |
http://secunia.com/advisories/15405 | third party advisory patch |
http://www.osvdb.org/16661 | vdb entry vendor advisory |
http://www.osvdb.org/16660 | vdb entry patch |