← Volver a CVEs
CVE-2007-4282
N/ADescripcion
The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado8/9/2007
Ultima modificacion4/23/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
serendipity:serendipity
Referencias
http://blog.drinsama.de/erich/en/security/2007080801-security-issue-in-serendipity.html(cve@mitre.org)
http://blog.s9y.org/archives/178-Serendipity-1.1.4-released%2C-security-bug-in-entryproperties-plugin.html(cve@mitre.org)
http://osvdb.org/36534(cve@mitre.org)
http://secunia.com/advisories/26347(cve@mitre.org)
http://sourceforge.net/forum/forum.php?forum_id=722867(cve@mitre.org)
http://www.securityfocus.com/bid/25235(cve@mitre.org)
https://exchange.xforce.ibmcloud.com/vulnerabilities/35868(cve@mitre.org)
http://blog.drinsama.de/erich/en/security/2007080801-security-issue-in-serendipity.html(af854a3a-2127-422b-91ae-364da2661108)
http://blog.s9y.org/archives/178-Serendipity-1.1.4-released%2C-security-bug-in-entryproperties-plugin.html(af854a3a-2127-422b-91ae-364da2661108)
http://osvdb.org/36534(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/26347(af854a3a-2127-422b-91ae-364da2661108)
http://sourceforge.net/forum/forum.php?forum_id=722867(af854a3a-2127-422b-91ae-364da2661108)
http://sourceforge.net/project/shownotes.php?group_id=75065&release_id=530716(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/25235(af854a3a-2127-422b-91ae-364da2661108)
https://exchange.xforce.ibmcloud.com/vulnerabilities/35868(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.