Candidate: CVE-2015-6968 PublicDate: 2015-09-16 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6968 http://seclists.org/fulldisclosure/2015/Sep/6 http://blog.s9y.org/archives/265-Serendipity-2.0.2-Security-Fix-Release.html http://packetstormsecurity.com/files/133426/Serendipity-2.0.1-Shell-Upload.html http://blog.curesec.com/article/blog/Serendipity-201-Code-Execution-48.html Description: Multiple incomplete blacklist vulnerabilities in the serendipity_isActiveFile function in include/functions_images.inc.php in Serendipity before 2.0.2 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .pht or (2) .phtml extension. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_serendipity: upstream: https://github.com/s9y/Serendipity/commit/dfd229f921e66b992843461cd2a09ee17fc3ce28 upstream_serendipity: released (2.0.2) precise_serendipity: ignored (reached end-of-life) precise/esm_serendipity: DNE (precise was needed) trusty_serendipity: DNE trusty/esm_serendipity: DNE vivid_serendipity: DNE vivid/stable-phone-overlay_serendipity: DNE vivid/ubuntu-core_serendipity: DNE wily_serendipity: DNE xenial_serendipity: DNE yakkety_serendipity: DNE zesty_serendipity: DNE devel_serendipity: DNE