20080422 Correcting CVEs (was Re: [Full-disclosure] Cross site scripting issues in s9y (CVE-2008-1386, CVE-2008-1387))mailing list
http://archives.neohapsis.com/archives/fulldisclosure/2008-04/0590.html CVE-2008-1385
S9Y Serendipity 1.3 - Referer HTTP Header Cross-Site Scripting
Record summary
CVE-2008-1385 has a selected CVSS score of 4.3; EIP currently links 1 catalogued exploit.
Description
Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBS9Y Serendipity 1.3 - Referer HTTP Header Cross-Site ScriptingExploitDB exploitby Hanno BoeckNot analyzed1 file
References
10blog.s9y.orgConfirmation
http://blog.s9y.org/archives/193-Serendipity-1.3.1-released.html int21.de
http://int21.de/cve/CVE-2008-1385-s9y.html 29942Third-party advisory
http://secunia.com/advisories/29942 20080422 Correcting CVEs (was Re: [Full-disclosure] Cross site scripting issues in s9y (CVE-2008-1386, CVE-2008-1387))mailing list
http://www.securityfocus.com/archive/1/491176/100/0/threaded 28885vdb entry
http://www.securityfocus.com/bid/28885 1019915vdb entry
http://www.securitytracker.com/id?1019915 ADV-2008-1348vdb entry
http://www.vupen.com/english/advisories/2008/1348/references topreferrers-referer-xss(41965)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41965 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-1385