Sample feed injecting code:
<rss version="2.0"> <channel><item><title>foo</title> <link>" onMouseOver="alert(1)</link></item></channel> </rss>
Serendipity developers have fixed this in svn and all further version, please update to 1.2.1 or above.
The Common Vulnerabilities and Exposures (CVE) project has assigned the name CVE-2007-6205 to this issue. This is a candidate for inclusion in the CVE list (http://cve.mitre.org/), which standardizes names for security problems.
This vulnerability was discovered by Hanno Boeck of schokokeks.org webhosting. It's licensed under the creative commons attribution license.
Hanno Boeck, 2007-12-05, http://www.hboeck.de