Hardened-PHP Project Security Advisory - Serendipity Weblog XSS Vulnerabilities: Serendipity failed to correctly sanitize user input on the media manager administration page. The content of GET variables were written into JavaScript strings. By using standard string evasion techniques it was possible to execute arbitrary JavaScript.
Hardened-PHP Project Security Advisory - Serendipity Weblog XSS Vulnerabilities: Serendipity failed to correctly sanitize user input on the media manager administration page. The content of GET variables were written into JavaScript strings. By using standard string evasion techniques it was possible to execute arbitrary JavaScript.