CVE-2016-10082: Critical severity serendipity vulnerability
include/functionsinstaller.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it fails to sanitize the dbType POST parameter before adding it to an include() call in the bundled-libs/serendipitygenerateFTPChecksums.php file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10082?
CVE-2016-10082 is rated as a critical vulnerability that can lead to file inclusion and potential code execution.
How do I fix CVE-2016-10082?
To fix CVE-2016-10082, upgrade to Serendipity version 2.0.6 or later that addresses the vulnerability.
Who is affected by CVE-2016-10082?
CVE-2016-10082 affects users running Serendipity versions up to and including 2.0.5.
What kind of attack does CVE-2016-10082 allow?
CVE-2016-10082 allows for file inclusion vulnerabilities that can lead to code execution during installation.
When was CVE-2016-10082 reported?
CVE-2016-10082 was reported in 2016, with versions affected including Serendipity through 2.0.5.