Back
CVE-2005-1134
SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.
Published: Apr 13, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (18)
| Vendor | Product | Version |
|---|---|---|
| s9y | serendipity | 0.3 |
| s9y | serendipity | 0.4 |
| s9y | serendipity | 0.5 |
| s9y | serendipity | 0.5_pl1 |
| s9y | serendipity | 0.6 |
| s9y | serendipity | 0.6_pl1 |
| s9y | serendipity | 0.6_pl2 |
| s9y | serendipity | 0.6_pl3 |
| s9y | serendipity | 0.6_rc1 |
| s9y | serendipity | 0.6_rc2 |
| s9y | serendipity | 0.7 |
| s9y | serendipity | 0.7_beta1 |
| s9y | serendipity | 0.7_beta2 |
| s9y | serendipity | 0.7_beta3 |
| s9y | serendipity | 0.7_beta4 |
| s9y | serendipity | 0.7_rc1 |
| s9y | serendipity | 0.8_beta5 |
| s9y | serendipity | 0.8_beta6 |
GitHub Security Advisory GHSA-c2p6-68h2-h25q
SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers...
References (16)
- http://seclists.org/lists/bugtraq/2005/Apr/0195.html
- http://secunia.com/advisories/15145 Patch, Vendor Advisory
- http://securitytracker.com/id?1013699 Vendor Advisory
- http://www.osvdb.org/15542 Vendor Advisory
- http://www.s9y.org/5.html Patch, Vendor Advisory
- http://www.s9y.org/63.html#A9 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/13161 Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/20119
- http://seclists.org/lists/bugtraq/2005/Apr/0195.html
- http://secunia.com/advisories/15145 Patch, Vendor Advisory
- http://securitytracker.com/id?1013699 Vendor Advisory
- http://www.osvdb.org/15542 Vendor Advisory
- http://www.s9y.org/5.html Patch, Vendor Advisory
- http://www.s9y.org/63.html#A9 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/13161 Exploit, Patch, Vendor Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.75%
Top 24% most likely to be exploited
Threat Score
30.5 / 100
Data Sources
NVD
EPSS
GitHub