Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2010-1916

The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers to bypass intended access restrictions and modify the configuration of arbitrary plugins via (1) crafted backend_config_secret_key_location and backend_config_hash parameters that are used in a SHA1 hash of a shared secret that can be known or externally influenced, which are not properly handled by the "Deprecated config passing" feature; or (2) crafted backend_data and backend_data[key_location] variables, which are not properly handled by the xinha_read_passed_data function. NOTE: this can be leveraged to upload and possibly execute arbitrary files via config.inc.php in the ImageManager plugin.

  • Published: May 12, 2010
  • Updated: Apr 13, 2023
  • CVE: CVE-2010-1916
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
xinha / wysiwyg_editor 0.9-beta 0.9-beta.x
xinha / wysiwyg_editor 0.91-beta 0.91-beta.x
xinha / wysiwyg_editor 0.92-beta 0.92-beta.x
xinha / wysiwyg_editor 0.93 0.93.x
xinha / wysiwyg_editor 0.94 0.94.x
xinha / wysiwyg_editor 0.95 0.95.x
xinha / wysiwyg_editor 0.96-beta2 0.96-beta2.x
xinha / wysiwyg_editor 0.96-beta 0.96-beta.x
s9y / serendipity 0.3 0.3.x
s9y / serendipity 0.4 0.4.x
s9y / serendipity 0.5-pl1 0.5-pl1.x
s9y / serendipity 0.6-pl3 0.6-pl3.x
s9y / serendipity 0.7 0.7.x
s9y / serendipity 0.7.1 0.7.1.x
s9y / serendipity 0.8 0.8.x
s9y / serendipity 0.8.1 0.8.1.x
s9y / serendipity 0.8.2 0.8.2.x
s9y / serendipity 0.8.3 0.8.3.x
s9y / serendipity 0.8.4 0.8.4.x
s9y / serendipity 0.8.5 0.8.5.x
s9y / serendipity 0.9 0.9.x
s9y / serendipity 0.9.1 0.9.1.x
s9y / serendipity 1.0 1.0.x
s9y / serendipity 1.0.1 1.0.1.x
s9y / serendipity 1.0.2 1.0.2.x
s9y / serendipity 1.0.3 1.0.3.x
s9y / serendipity 1.0.4 1.0.4.x
s9y / serendipity 1.1 1.1.x
s9y / serendipity 1.1.1 1.1.1.x
s9y / serendipity 1.1.2 1.1.2.x
s9y / serendipity 1.1.3 1.1.3.x
s9y / serendipity 1.1.4 1.1.4.x
s9y / serendipity 1.2 1.2.x
s9y / serendipity 1.2.1 1.2.1.x
s9y / serendipity 1.3 1.3.x
s9y / serendipity 1.3.1 1.3.1.x
s9y / serendipity 1.4 1.4.x
s9y / serendipity 1.4.1 1.4.1.x
s9y / serendipity 1.5 1.5.x
s9y / serendipity 1.5.1 1.5.1.x
s9y / serendipity 1.5.2 1.5.2.x