Hardened-PHP Project Security Advisory – Serendipity Weblog XSS Vulnerabilities: Serendipity failed to correctly sanitize user input on the media manager administration page. The content of GET variables were written into JavaScript strings. By using standard string evasion techniques it was possible to execute arbitrary JavaScript.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/51265/Serendipity-1.0.1.txt
Source: https://packetstormsecurity.com/files/51265/Serendipity-1.0.1.txt.html