CVE
- Id
- 10583
- CVE No.
- CVE-2004-2157
- Status
- Candidate
- Description
- Cross-site scripting (XSS) vulnerability in Comment.php in Serendipity 0.7 beta1, and possibly other versions before 0.7-beta3, allows remote attackers to inject arbitrary HTML and PHP code via the (1) email or (2) username field.
- Phase
- Assigned (20050710)
- Votes
- None (candidate not yet proposed)
- Comments