Show filters
57 Total Results
Displaying 41-50 of 57
Sort by:
Attacker Value
Unknown

CVE-2013-4556

Disclosure Date: November 18, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter.
0
Attacker Value
Unknown

CVE-2013-4557

Disclosure Date: November 18, 2013 (last updated October 05, 2023)
The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execute arbitrary PHP via the connect parameter.
0
Attacker Value
Unknown

CVE-2013-2118

Disclosure Date: July 09, 2013 (last updated October 05, 2023)
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.
0
Attacker Value
Unknown

CVE-2012-2151

Disclosure Date: August 14, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-4331

Disclosure Date: August 14, 2012 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vectors that are not related to cross-site scripting (XSS), different vulnerabilities than CVE-2012-2151.
0
Attacker Value
Unknown

CVE-2009-3041

Disclosure Date: September 01, 2009 (last updated October 04, 2023)
SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.
0
Attacker Value
Unknown

CVE-2008-5813

Disclosure Date: January 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in inc/rubriques.php in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-5812

Disclosure Date: January 02, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 have unknown impact and attack vectors.
0
Attacker Value
Unknown

CVE-2007-4525

Disclosure Date: August 25, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the squelette_cache parameter, a different vector than CVE-2006-1702. NOTE: this issue has been disputed by third party researchers, stating that the squelette_cache variable is initialized before use, and is only used within the scope of a function
0
Attacker Value
Unknown

CVE-2006-1702

Disclosure Date: April 11, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in spip_login.php3 in SPIP 1.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.
0