Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
| Software | From | Fixed in |
|---|---|---|
| s9y / serendipity | 0.8_beta5 | 0.8_beta5.x |
| s9y / serendipity | 0.7 | 0.7.x |
| s9y / serendipity | 0.7_beta1 | 0.7_beta1.x |
| s9y / serendipity | 0.7.1 | 0.7.1.x |
| s9y / serendipity | 0.7_beta3 | 0.7_beta3.x |
| s9y / serendipity | 0.8_beta6 | 0.8_beta6.x |
| s9y / serendipity | 0.7_beta4 | 0.7_beta4.x |
| s9y / serendipity | 0.7_beta2 | 0.7_beta2.x |
| s9y / serendipity | 0.7_rc1 | 0.7_rc1.x |