First published: Tue Nov 05 2019(Updated: )
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/ImageManager/manager.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/dotlrn | ||
debian/openacs | ||
debian/serendipity | ||
Serendipity (S9Y) Freetag Event | <1.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1135 is a vulnerability that allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/ImageManager/manager.php in the Serendipity package before version 1.5.5.
The severity of CVE-2011-1135 is medium, with a severity value of 6.1.
To fix CVE-2011-1135, you should update the Serendipity package to version 1.5.5 or later.
You can find more information about CVE-2011-1135 in the following references: [Link 1](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=611661), [Link 2](https://blog.s9y.org/archives/224-Important-Security-Update-Serendipity-1.5.5-released.html), [Link 3](https://security-tracker.debian.org/tracker/CVE-2011-1135).
The CWE of CVE-2011-1135 is CWE-79, which stands for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').