Description
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Special Text Boxes Unspecified Vulnerability (5.5.102)
IBM WebSEAL Missing Authorization Vulnerability (CVE-2019-4158)
Lighttpd Other Vulnerability (CVE-2008-1531)
Oracle Application Server Other Vulnerability (CVE-2005-1383)
WordPress Plugin WP Selected Text Sharer Multiple Vulnerabilities (1.0)