Show filters
57 Total Results
Displaying 21-30 of 57
Sort by:
Attacker Value
Unknown

CVE-2019-19830

Disclosure Date: December 17, 2019 (last updated November 27, 2024)
_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database.
Attacker Value
Unknown

CVE-2019-16393

Disclosure Date: September 17, 2019 (last updated November 27, 2024)
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
Attacker Value
Unknown

CVE-2019-16392

Disclosure Date: September 17, 2019 (last updated November 27, 2024)
SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
Attacker Value
Unknown

CVE-2019-16394

Disclosure Date: September 17, 2019 (last updated November 27, 2024)
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.
Attacker Value
Unknown

CVE-2019-16391

Disclosure Date: September 17, 2019 (last updated November 27, 2024)
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
Attacker Value
Unknown

CVE-2019-11071

Disclosure Date: April 10, 2019 (last updated November 27, 2024)
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.
0
Attacker Value
Unknown

CVE-2017-15736

Disclosure Date: October 22, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web script or HTML via a crafted string, as demonstrated by a PGP field, related to prive/objets/contenu/auteur.html and ecrire/inc/texte_mini.php.
0
Attacker Value
Unknown

CVE-2017-9736

Disclosure Date: June 17, 2017 (last updated November 26, 2024)
SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution.
0
Attacker Value
Unknown

CVE-2016-7998

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with a valider_xml action.
0
Attacker Value
Unknown

CVE-2016-7999

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the var_url parameter in a valider_xml action.
0