Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2013-5670

Published: 5 November 2013

Cross-site scripting (XSS) vulnerability in spell-check-savedicts.php in the htmlarea SpellChecker module, as used in Serendipity before 1.7.3 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the to_r_list parameter.

Notes

AuthorNote
mdeslaur
doesn't affect 1.5.x

Priority

Medium

Status

Package Release Status
serendipity
Launchpad, Ubuntu, Debian
lucid Ignored
(end of life)
precise Not vulnerable

quantal Not vulnerable

raring Not vulnerable

upstream Needs triage