Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2016-3153
Disclosure Date: April 08, 2016 (last updated November 25, 2024)
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrer_entites function.
0
Attacker Value
Unknown
CVE-2016-3154
Disclosure Date: April 08, 2016 (last updated November 25, 2024)
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
0
Attacker Value
Unknown
CVE-2013-7303
Disclosure Date: January 30, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in (1) squelettes-dist/formulaires/inscription.php and (2) prive/forms/editer_auteur.php in SPIP before 2.1.25 and 3.0.x before 3.0.13 allow remote attackers to inject arbitrary web script or HTML via the author name field.
0
Attacker Value
Unknown
CVE-2013-4555
Disclosure Date: November 18, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in SPIP before 2.1.24 allows remote attackers to hijack the authentication of arbitrary users for requests that logout the user via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-4556
Disclosure Date: November 18, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter.
0
Attacker Value
Unknown
CVE-2013-2118
Disclosure Date: July 09, 2013 (last updated October 05, 2023)
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.
0
Attacker Value
Unknown
CVE-2009-3041
Disclosure Date: September 01, 2009 (last updated October 04, 2023)
SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.
0