Show filters
55 Total Results
Displaying 41-50 of 55
Sort by:
Attacker Value
Unknown
CVE-2013-2118
Disclosure Date: July 09, 2013 (last updated October 05, 2023)
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.
0
Attacker Value
Unknown
CVE-2012-2151
Disclosure Date: August 14, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-4331
Disclosure Date: August 14, 2012 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vectors that are not related to cross-site scripting (XSS), different vulnerabilities than CVE-2012-2151.
0
Attacker Value
Unknown
CVE-2009-3041
Disclosure Date: September 01, 2009 (last updated October 04, 2023)
SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.
0
Attacker Value
Unknown
CVE-2008-5813
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in inc/rubriques.php in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-5812
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 have unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2007-4525
Disclosure Date: August 25, 2007 (last updated November 08, 2023)
PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the squelette_cache parameter, a different vector than CVE-2006-1702. NOTE: this issue has been disputed by third party researchers, stating that the squelette_cache variable is initialized before use, and is only used within the scope of a function
0
Attacker Value
Unknown
CVE-2006-1702
Disclosure Date: April 11, 2006 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in spip_login.php3 in SPIP 1.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.
0
Attacker Value
Unknown
CVE-2006-1295
Disclosure Date: March 19, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.
0
Attacker Value
Unknown
CVE-2006-0626
Disclosure Date: February 09, 2006 (last updated February 22, 2025)
SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter.
0