Serendipity

Serendipity is a PHP-powered weblog engine that gives the user an easy way to maintain a blog.

Severity Summary:

Critical: 6 High: 13 Medium: 26 Low: 2
Reference
Title
Severity
Serendipity Unrestricted Upload of File with Dangerous Type Vulnerability
Critical
Serendipity Remote Code Execution
Critical
Serendipity Other Vulnerability
Critical
Serendipity Unrestricted Upload of File with Dangerous Type Vulnerability
Critical
Serendipity Improper Access Control Vulnerability
Critical
Serendipity Other Vulnerability
Critical
Serendipity Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Serendipity Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Serendipity Other Vulnerability
High
Serendipity Permissions Privileges and Access Controls Vulnerability
High
Serendipity Other Vulnerability
High
Serendipity Other Vulnerability
High
Serendipity Server-Side Request Forgery (SSRF) Vulnerability
High
Serendipity Other Vulnerability
High
Serendipity Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Serendipity Cross-Site Request Forgery (CSRF) Vulnerability
High
Serendipity Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Serendipity Cross-Site Request Forgery (CSRF) Vulnerability
High
Serendipity Cross-Site Request Forgery (CSRF) Vulnerability
High
Serendipity Other Vulnerability
Medium
Serendipity Other Vulnerability
Medium
Serendipity Other Vulnerability
Medium
Serendipity Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Medium
Serendipity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Serendipity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Serendipity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Serendipity Other Vulnerability
Medium
Serendipity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Serendipity Other Vulnerability
Medium
Serendipity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium