Multiple cross-site scripting (XSS) vulnerabilities in the installer in Serendipity (S9Y) 1.3 allow remote attackers to inject arbitrary web script or HTML via (1) unspecified path fields or (2) the database host field. NOTE: the timing window for exploitation of this issue might be limited.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2008-04-23T10:00:00
Updated: 2024-08-07T08:17:34.678Z
Reserved: 2008-03-18T00:00:00
Link: CVE-2008-1386
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-04-23T13:05:00.000
Modified: 2024-11-21T00:44:25.510
Link: CVE-2008-1386
Redhat
No data.