Description
Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in plugins/ExtendedFileManager/manager.php and plugins/ImageManager/manager.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ultimate WordPress Auction Cross-Site Request Forgery (1.0.0)
Oracle JRE CVE-2013-3829 Vulnerability (CVE-2013-3829)
WordPress Plugin Integration for Gravity Forms and Pipedrive Cross-Site Scripting (1.0.6)
Apache Tomcat Improper Input Validation Vulnerability (CVE-2013-4322)
WordPress Plugin Enable Media Replace Unspecified Vulnerability (2.9.5)