Description
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/ImageManager/manager.php.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-1999-1233)
WordPress Plugin uContext for Amazon Cross-Site Request Forgery (3.9.1)
WordPress Plugin Gallery for Social Photo Cross-Site Request Forgery (1.0.0.27)
PHP Improper Access Control Vulnerability (CVE-2015-8838)
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2009-3294)