CVE-2007-4282

NameCVE-2007-4282
DescriptionThe "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
serendipitysourceetch(not affected)
serendipitysource(unstable)1.1.4-1

Notes

[etch] - serendipity <not-affected> (introduced in 1.1.x)

Search for package or bug name: Reporting problems