CVE-2004-2157: XSS
Cross-site scripting (XSS) vulnerability in Comment.php in Serendipity 0.7 beta1, and possibly other versions before 0.7-beta3, allows remote attackers to inject arbitrary HTML and PHP code via the (1) email or (2) username field.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2157?
CVE-2004-2157 is rated as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2004-2157?
To fix CVE-2004-2157, upgrade to Serendipity version 0.7-beta3 or later, which addresses this XSS vulnerability.
What systems are affected by CVE-2004-2157?
CVE-2004-2157 affects Serendipity version 0.7 beta1 and possibly earlier versions before 0.7-beta3.
What types of attacks can be performed using CVE-2004-2157?
CVE-2004-2157 allows attackers to inject arbitrary HTML and PHP code, facilitating cross-site scripting attacks.
Are there known exploits for CVE-2004-2157?
Yes, there are known exploits that leverage the cross-site scripting vulnerability in CVE-2004-2157 to execute malicious scripts.