Description
Cross-site scripting (XSS) vulnerability in templates/2k11/admin/entries.tpl in Serendipity before 2.0.1 allows remote authenticated editors to inject arbitrary web script or HTML via the serendipity[cat][name] parameter to serendipity_admin.php, when creating a new category.
Remediation
References
Related Vulnerabilities
WordPress Plugin PowerPress Podcasting by Blubrry Cross-Site Scripting (10.0.1)
WordPress Plugin Limit Login Attempts Reloaded Security Bypass (2.7.4)
OpenSSL Other Vulnerability (CVE-2015-3194)
Apache version older than 1.3.37
WordPress Plugin Easy Digital Downloads-htaccess Editor Cross-Site Scripting (1.0.0)