Description
Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.
Remediation
References
Related Vulnerabilities
OpenSSL Out-of-bounds Read Vulnerability (CVE-2016-2180)
WordPress Plugin Broken Link Manager Multiple Vulnerabilities (0.4.5)
WordPress Plugin Post to CSV by BestWebSoft Cross-Site Scripting (1.3.0)
Microsoft SQL Server Other Vulnerability (CVE-2001-0542)
Envoy Proxy Excessive Iteration Vulnerability (CVE-2021-39204)