|
Family: CGI abuses : XSS --> Category: attack
Serendipity HTTP Response Splitting Vulnerability Vulnerability Scan
Vulnerability Scan Summary Searches for the existence of Serendipity
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP application that is affected by a
cross-site scripting flaw.
Description :
The remote version of Serendipity is vulnerable to an HTTP response-
splitting vulnerability that may allow a possible hacker to perform a cross-
site scripting attack against the remote host.
See also :
http://archives.neohapsis.com/archives/bugtraq/2004-10/0219.html
http://www.s9y.org/5.html
Solution :
Upgrade to Serendipity 0.7rc1 or newer.
Threat Level:
Low / CVSS Base Score : 2
(AV:R/AC:H/Au:NR/C:N/A:N/I:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|