Description
Cross-site scripting (XSS) vulnerability in serendipity_admin_image_selector.php in Serendipity 1.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the serendipity[htmltarget] parameter.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ninja Forms with File Uploads Extension Arbitrary File Upload (3.3.0)
WordPress Plugin Exit Popups & Onsite Retargeting by OptiMonk Cross-Site Scripting (1.2.5)
Oracle Application Server Other Vulnerability (CVE-2006-5357)
Drupal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2010-2471)