Title: Serendipity Media Upload Path Validation Failure
Info
Disclosure
Apr 26, 2005
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
Serendipity contains a flaw related to the validation of path names that may allow a remote attacker to upload files to arbitrary locations. No further details have been provided.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified,
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 0.8 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.