Serendipity is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Credit:
The information has been provided by High-Tech Bridge SA .
The original article can be found at: http://www.securityfocus.com/bid/53620
Vulnerable Systems:
* Serendipity Serendipity 1.6.1
* Serendipity Serendipity 1.5.5
* Serendipity Serendipity 1.6
Immune Systems:
* Serendipity Serendipity 1.6.2
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Vendor Status:
Serendipity had issued an update for this vulnerability
Patch Availability:
http://blog.s9y.org/archives/241-Serendipity-1.6.2-released.html
CVE Information:
CVE-2012-2762
Disclosure Timeline:
Initial Release: May 16 2012
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by