PublicDate: 2008-04-23 13:05:00 UTC Candidate: CVE-2008-1385 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1385 Description: Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_serendipity: upstream_serendipity: released (1.3.1) dapper_serendipity: DNE feisty_serendipity: needed (reached end-of-life) gutsy_serendipity: needed (reached end-of-life) hardy_serendipity: ignored (reached end-of-life) intrepid_serendipity: not-affected (1.3.1-1) jaunty_serendipity: not-affected (1.3.1-1) karmic_serendipity: not-affected (1.3.1-1) lucid_serendipity: not-affected (1.3.1-1) maverick_serendipity: not-affected (1.3.1-1) natty_serendipity: not-affected (1.3.1-1) oneiric_serendipity: not-affected (1.3.1-1) devel_serendipity: not-affected (1.3.1-1)