CVE-2008-0751
serendipity_event_freetag < 2.96 - Cross-Site Scripting via PATH_INFO
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0751. PoCs published by Alexander Brachmann.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in the Serendipity Freetag-plugin, where user-supplied data is not sufficiently sanitized. The example URL demonstrates how an attacker could inject malicious scripts via the tag parameter.
Description
Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to plugin/tag/.
Exploits (1)
The provided text describes a cross-site scripting (XSS) vulnerability in the Serendipity Freetag-plugin, where user-supplied data is not sufficiently sanitized. The example URL demonstrates how an attacker could inject malicious scripts via the tag parameter.