First published: Tue May 24 2005(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Serendipity (S9Y) Freetag Event | =0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1713 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2005-1713, update Serendipity to a version higher than 0.8 that addresses these vulnerabilities.
The attack vectors for CVE-2005-1713 include the templatedropdown and shoutbox plugins that can be exploited for XSS.
Users of Serendipity version 0.8 are at risk of remote attackers injecting malicious web scripts through vulnerable plugins.
To determine if your site is affected by CVE-2005-1713, check if you are using Serendipity version 0.8 and the mentioned plugins.