Back

CVE-2004-2158

SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter to (1) exit.php or (2) comment.php.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
s9y serendipity 0.7_beta1

GitHub Security Advisory GHSA-h3p6-jrr8-w6jh

SQL injection vulnerability in Serendipity 0.7-beta1 allows remote attackers to execute arbitrary...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 4.11%

Top 10% most likely to be exploited

Threat Score 31.2 / 100

Data Sources

NVD EPSS GitHub