Serendipity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2008-1385 - Vulnerability Database

Serendipity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2008-1385

Medium
Reference: CVE-2008-1385
Title: Serendipity Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.