« Volver al listado

CVE-2010-1916

Estado: ModificadaAlta (7.5)—

The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers to bypass intended access restrictions and modify the configuration of arbitrary plugins via (1) crafted backend_config_secret_key_location and backend_config_hash parameters that are used in a SHA1 hash of a shared secret that can be known or externally influenced, which are not properly handled by the "Deprecated config passing" feature; or (2) crafted backend_data and backend_data[key_location] variables, which are not properly handled by the xinha_read_passed_data function. NOTE: this can be leveraged to upload and possibly execute arbitrary files via config.inc.php in the ImageManager plugin.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-1916",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-05-12T11:46:40.313",
  "references": [
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042577.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/39782",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/40124",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://trac.xinha.org/ticket/1518",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.php-security.org/2010/05/10/mops-2010-019-serendipity-wysiwyg-editor-plugin-configuration-injection-vulnerability/index.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.php-security.org/2010/05/10/mops-2010-020-xinha-wysiwyg-plugin-configuration-injection-vulnerability/index.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/40033",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1401",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=591701",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-June/042577.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/39782",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/40124",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://trac.xinha.org/ticket/1518",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.php-security.org/2010/05/10/mops-2010-019-serendipity-wysiwyg-editor-plugin-configuration-injection-vulnerability/index.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.php-security.org/2010/05/10/mops-2010-020-xinha-wysiwyg-plugin-configuration-injection-vulnerability/index.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/40033",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1401",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=591701",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers to bypass intended access restrictions and modify the configuration of arbitrary plugins via (1) crafted backend_config_secret_key_location and backend_config_hash parameters that are used in a SHA1 hash of a shared secret that can be known or externally influenced, which are not properly handled by the \"Deprecated config passing\" feature; or (2) crafted backend_data and backend_data[key_location] variables, which are not properly handled by the xinha_read_passed_data function.  NOTE: this can be leveraged to upload and possibly execute arbitrary files via config.inc.php in the ImageManager plugin."
    },
    {
      "lang": "es",
      "value": "La funcionalidad de configuración dinámica del editor Xinha WYSIWYG v0.96 Beta 2 y anteriores, como la utilizada en Serendipity v1.5.2 y anteriores, permite a atacantes remotos evitar las restricciones de acceso pretendidas y modificar la configuración de complementos -plugins- de su elección mediante (1) los parámetros modificados backend_config_secret_key_location y backend_config_hash que se utilizan en un hash SHA1 de un secreto compartido que pueden ser conocidos o influenciados externamente, los cuales no son manejados adecuadamente por la funcionalidad \"Deprecated config passing\"; o (2) las variables manipuladas backend_data y backend_data[key_location], las cuales no son manejadas adecuadamente por la función xinha_read_passed_data. NOTA: Esto puede ser aprovechado para subir y puede que ejecutar los ficheros que se deseen mediante el fichero config.inc.php del complemento ImageManager plugin."
    }
  ],
  "lastModified": "2026-06-16T23:19:35.033",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:xinha:wysiwyg_editor:0.9:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC6539B7-3759-4BEC-A41E-963C639F3D92"
            },
            {
              "criteria": "cpe:2.3:a:xinha:wysiwyg_editor:0.91:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E49B705C-DE5F-4DB5-96C6-3AA33B172A8B"
            },
            {
              "criteria": "cpe:2.3:a:xinha:wysiwyg_editor:0.92:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E63C90F4-78A4-4532-B85C-C619FC803F2A"
            },
            {
              "criteria": "cpe:2.3:a:xinha:wysiwyg_editor:0.93:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F303DC9-EDA4-4E99-8B8B-A1867F125A44"
            },
            {
              "criteria": "cpe:2.3:a:xinha:wysiwyg_editor:0.94:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E71A44B7-ADFA-4E2C-8744-DD55DE409ACB"
            },
            {
              "criteria": "cpe:2.3:a:xinha:wysiwyg_editor:0.95:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8B59CDE-D0CE-42D5-9221-22F7B55BA4C6"
            },
            {
              "criteria": "cpe:2.3:a:xinha:wysiwyg_editor:0.96:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D96327E-17D2-4100-A9A6-BC5741FC5125"
            },
            {
              "criteria": "cpe:2.3:a:xinha:wysiwyg_editor:0.96:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25254A30-6E90-4232-9D68-491E0BB06141"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62233D77-9838-48AB-9A2D-F4EAA9E237EB"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A6F23BF-1C25-4A5E-9EC4-35A1A821A235"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.5:pl1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A65D59D-DDFF-4551-987C-D449A4C6F57A"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.6:pl3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "894A8EF2-0014-49CB-9947-65E1C3CDE0D5"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "925A50B9-0CEF-42FF-8359-52BAFB4FEBB5"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C739BCD2-1722-42E0-9560-752DBBF05BC1"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B7515A9A-1FD0-484E-97CB-5969729804DB"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.8.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40A451C0-D4D8-43FF-BFC9-E525138DCA37"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E1F8976-0691-4C47-9BA3-BC01BA808BE3"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.8.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B2FF146-8CEF-48C8-81A3-08B4736DC27D"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.8.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5986FA95-D0F8-4E41-A445-F2F0EFEE872A"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.8.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "22A4B77F-67DC-4D25-8948-0C0B59C38E07"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E24AD8E2-AEB7-4D73-9B15-AE0B293A0825"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:0.9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47CE7E31-9C42-434E-B1B7-F38966514405"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F5193D1-4BB6-4B2C-8361-BA1C7BE7524B"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B62B695-74A2-49AA-87EF-38F129A94755"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D4ACB96-F32D-40E2-A9F3-A3CD78658C4F"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6B027CFC-5E0E-45D3-82BC-8F59F386D188"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3C6CB12-9D14-4D5C-8FC0-02179436B487"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23D55BCF-58D1-48D8-9BA2-2884F6126F8F"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "707176E4-B735-4A6A-AC7D-01250663D25D"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0132EF3F-F9D8-4CEC-A774-4929B4DE6E55"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2217392-37F3-4CC6-85DE-33CB8841814F"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "706E7CF6-C396-4A19-B87C-05BA8C8D9EE9"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0C422BF-FBDE-4DD2-BB55-868B19890479"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1E92848-05FA-45EE-BD8A-98E337131892"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96AD0492-E4D4-4A43-80EF-5F38F62DFF25"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B176479-5EFB-4943-801A-676B74C04DDA"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D68BD0B3-FB77-4288-93F4-2E018789D858"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E6CE765-5EA9-4E38-8EB4-2913CEBE5F44"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE962E7C-08A3-44E4-B06D-E00A03C3DB16"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91A8DDF5-F344-4810-AAFA-31085CC8ED01"
            },
            {
              "criteria": "cpe:2.3:a:s9y:serendipity:1.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8058BE3F-6C1E-4B6D-922D-909022D897CB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}