Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-2331

Опубликовано: 13 авг. 2012
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 4.3

Описание

Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the serendipity[textarea] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF).

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

hardy

ignored

end of life
lucid

ignored

end of life
natty

ignored

end of life
oneiric

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

ignored

end of life
raring

ignored

end of life

Показывать по

EPSS

Процентиль: 94%
0.14788
Средний

4.3 Medium

CVSS2

Связанные уязвимости

nvd
больше 13 лет назад

Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the serendipity[textarea] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF).

debian
больше 13 лет назад

Cross-site scripting (XSS) vulnerability in serendipity/serendipity_ad ...

github
больше 3 лет назад

Cross-site scripting (XSS) vulnerability in serendipity/serendipity_admin_image_selector.php in Serendipity before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the serendipity[textarea] parameter. NOTE: this issue might be resultant from cross-site request forgery (CSRF).

EPSS

Процентиль: 94%
0.14788
Средний

4.3 Medium

CVSS2