Description
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code via plugins/ExtendedFileManager/backend.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Google Analytics Dashboard Multiple Unspecified Vulnerabilities (2.0.5)
Sqlite Use of Uninitialized Resource Vulnerability (CVE-2015-3414)
WordPress Plugin Fast Secure Contact Form-Clockwork SMS Cross-Site Scripting (2.1.2)
WordPress Plugin Bind Users to Taxonomy Cross-Site Scripting (0.3)
Magento XML Injection (aka Blind XPath Injection) Vulnerability (CVE-2021-21025)