Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2016-3153
Disclosure Date: April 08, 2016 (last updated November 25, 2024)
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrer_entites function.
0
Attacker Value
Unknown
CVE-2016-3154
Disclosure Date: April 08, 2016 (last updated November 25, 2024)
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
0
Attacker Value
Unknown
CVE-2013-4555
Disclosure Date: November 18, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in SPIP before 2.1.24 allows remote attackers to hijack the authentication of arbitrary users for requests that logout the user via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-4556
Disclosure Date: November 18, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter.
0
Attacker Value
Unknown
CVE-2013-2118
Disclosure Date: July 09, 2013 (last updated October 05, 2023)
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.
0
Attacker Value
Unknown
CVE-2009-3041
Disclosure Date: September 01, 2009 (last updated October 04, 2023)
SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.
0
Attacker Value
Unknown
CVE-2008-5813
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in inc/rubriques.php in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-5812
Disclosure Date: January 02, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 have unknown impact and attack vectors.
0