Serendipity 1.1.3 and 1.2-beta2 released
Jun 17th, 2007 | By opencm.de | Category: Blog-News“Serendipity 1.1.3 and 1.2-beta2 have been released due to a SQL injection attack reported by Dr. Neal Krawetz today. It is possible to abuse a ‘commentMode’ variable to inject SQL code that was targeted to the function that fetches comment information. This variable was introduced to Serendipity 1.1 – all prior versions are not affected.”