Hardened PHP Project
www.hardened-php.net
-= Security Advisory =-
Advisory: Remote code execution in Serendipity
Release Date: 2005/06/29
Last Modified: 2005/06/29
Author: Christopher Kunz <christopher.kunz@xxxxxxxxxxxxxxxx>
Application: Serendipity <= 0.8.2
Severity: Arbitrary remote code execution
Risk: Very High
Vendor Status: Vendor has released an updated version
References: http://www.hardened-php.net/advisory-022005.php
Overview:
Quote from http://www.s9y.org/:
"Serendipity is a weblog/blog system, implemented with PHP. It is
standards
compliant, feature rich and open source (BSD License). Serendipity is
constantly under active development, with a team of talented
developers
trying to make the best PHP powered blog on the net."
Details: