Show filters
55 Total Results
Displaying 21-30 of 55
Sort by:
Attacker Value
Unknown
CVE-2019-16392
Disclosure Date: September 17, 2019 (last updated November 27, 2024)
SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
0
Attacker Value
Unknown
CVE-2019-16394
Disclosure Date: September 17, 2019 (last updated November 27, 2024)
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.
0
Attacker Value
Unknown
CVE-2019-16391
Disclosure Date: September 17, 2019 (last updated November 27, 2024)
SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.
0
Attacker Value
Unknown
CVE-2019-11071
Disclosure Date: April 10, 2019 (last updated November 27, 2024)
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.
0
Attacker Value
Unknown
CVE-2017-15736
Disclosure Date: October 22, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web script or HTML via a crafted string, as demonstrated by a PGP field, related to prive/objets/contenu/auteur.html and ecrire/inc/texte_mini.php.
0
Attacker Value
Unknown
CVE-2017-9736
Disclosure Date: June 17, 2017 (last updated November 26, 2024)
SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution.
0
Attacker Value
Unknown
CVE-2016-7998
Disclosure Date: January 18, 2017 (last updated November 25, 2024)
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with a valider_xml action.
0
Attacker Value
Unknown
CVE-2016-7999
Disclosure Date: January 18, 2017 (last updated November 25, 2024)
ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the var_url parameter in a valider_xml action.
0
Attacker Value
Unknown
CVE-2016-7980
Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted valider_xml request. NOTE: this issue can be combined with CVE-2016-7998 to execute arbitrary PHP code.
0
Attacker Value
Unknown
CVE-2016-7981
Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.
0