CVE-2007-4282

high

Description

The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/35868

http://www.securityfocus.com/bid/25235

http://sourceforge.net/project/shownotes.php?group_id=75065&release_id=530716

http://sourceforge.net/forum/forum.php?forum_id=722867

http://secunia.com/advisories/26347

http://osvdb.org/36534

http://blog.s9y.org/archives/178-Serendipity-1.1.4-released%2C-security-bug-in-entryproperties-plugin.html

http://blog.drinsama.de/erich/en/security/2007080801-security-issue-in-serendipity.html

Details

Source: Mitre, NVD

Published: 2007-08-09

Updated: 2023-11-07

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Severity: High