SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via the cat parameter.
References
Link Resource
http://www.securityfocus.com/bid/95850 Third Party Advisory VDB Entry
https://github.com/s9y/Serendipity/commit/c62d667287f2d76c81e03a740a581eb3c51249b6 Issue Tracking Patch Third Party Advisory
https://github.com/s9y/Serendipity/releases/tag/2.1-rc1 Release Notes Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2017-01-28T18:00:00

Updated: 2017-03-23T09:57:01

Reserved: 2017-01-28T00:00:00


Link: CVE-2017-5609

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2017-01-28T18:59:00.180

Modified: 2019-03-19T15:12:50.700


Link: CVE-2017-5609

JSON object: View

cve-icon Redhat Information

No data.

CWE