Lucene search

K
cve[email protected]CVE-2008-0124
HistoryFeb 28, 2008 - 8:44 p.m.

CVE-2008-0124

2008-02-2820:44:00
CWE-79
web.nvd.nist.gov
24
cve-2008-0124
cross-site scripting
xss
serendipity
s9y
vulnerability
remote authenticated users
web script
html
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.8%

Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3-beta1 allows remote authenticated users to inject arbitrary web script or HTML via (1) the “Real name” field in Personal Settings, which is presented to readers of articles; or (2) a file upload, as demonstrated by a .htm, .html, or .js file.

Affected configurations

NVD
Node
s9yserendipityMatch0.3
OR
s9yserendipityMatch0.4
OR
s9yserendipityMatch0.5
OR
s9yserendipityMatch0.5_pl1
OR
s9yserendipityMatch0.6
OR
s9yserendipityMatch0.6_pl1
OR
s9yserendipityMatch0.6_pl2
OR
s9yserendipityMatch0.6_pl3
OR
s9yserendipityMatch0.6_rc1
OR
s9yserendipityMatch0.6_rc2
OR
s9yserendipityMatch0.7
OR
s9yserendipityMatch0.7.1
OR
s9yserendipityMatch0.7_beta1
OR
s9yserendipityMatch0.7_beta2
OR
s9yserendipityMatch0.7_beta3
OR
s9yserendipityMatch0.7_beta4
OR
s9yserendipityMatch0.7_rc1
OR
s9yserendipityMatch0.8
OR
s9yserendipityMatch0.8.1
OR
s9yserendipityMatch0.8.2
OR
s9yserendipityMatch0.8_beta_6_snapshot
OR
s9yserendipityMatch0.8_beta5
OR
s9yserendipityMatch0.8_beta6
OR
s9yserendipityMatch0.9.1
OR
s9yserendipityMatch1.0.3
OR
s9yserendipityMatch1.0.4
OR
s9yserendipityMatch1.0_beta2
OR
s9yserendipityMatch1.0_beta3
OR
s9yserendipityMatch1.1.1
OR
s9yserendipityMatch1.1.3
OR
s9yserendipityMatch1.1.4
OR
s9yserendipityMatch1.2
OR
s9yserendipityMatch1.2.1
OR
s9yserendipityMatch1.2__beta5

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

5.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.8%