Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-1386
Description:Multiple cross-site scripting (XSS) vulnerabilities in the installer in Serendipity (S9Y) 1.3 allow remote attackers to inject arbitrary web script or HTML via (1) unspecified path fields or (2) the database host field. NOTE: the timing window for exploitation of this issue might be limited.
Test IDs: 1.3.6.1.4.1.25623.1.0.60885  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-1386
BugTraq ID: 28885
http://www.securityfocus.com/bid/28885
Bugtraq: 20080422 Correcting CVEs (was Re: [Full-disclosure] Cross site scripting issues in s9y (CVE-2008-1386, CVE-2008-1387)) (Google Search)
http://www.securityfocus.com/archive/1/491176/100/0/threaded
http://archives.neohapsis.com/archives/fulldisclosure/2008-04/0590.html
http://int21.de/cve/CVE-2008-1386-s9y.html
http://www.securitytracker.com/id?1019915
http://www.vupen.com/english/advisories/2008/1348/references
XForce ISS Database: serendipity-installer-xss(41967)
https://exchange.xforce.ibmcloud.com/vulnerabilities/41967




© 1998-2025 E-Soft Inc. All rights reserved.