Launchpad.net

CVE 2011-1134

Cross-Site Scripting (XSS) in Xinha, as included in the Serendipity package before 1.5.5, allows remote attackers to execute arbitrary code in the image manager.

See the CVE page on Mitre.org for more details.

References