CVE-2007-4282

Publication date 9 August 2007

Last updated 17 July 2025


Ubuntu priority

Description

The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked.

Status

Package Ubuntu Release Status
serendipity 8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
7.04 feisty Ignored end of life, was needed
6.10 edgy Not in release
6.06 LTS dapper Not in release