[38374] in bugtraq
Re: serendipity SQL Injection vulnerability
daemon@ATHENA.MIT.EDU (sebastian@nohn.net)
Thu Apr 14 19:22:17 2005
Date: 14 Apr 2005 18:08:40 -0000
Message-ID: <20050414180840.32314.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: <sebastian@nohn.net>
To: bugtraq@securityfocus.com
In-Reply-To: <20050413202205.7e0c8bb1@xaero.tvpro.net>
>Program: serentdipity web blog system
>Version: 0.8beta4
>Module: exit.php
>Bug type: SQL Injection
>Vendor site: http://www.s9y.org/
>Vendor Informed: Yes
The vendor has NOT been informed.