Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2016-3153

Disclosure Date: April 08, 2016 (last updated November 25, 2024)
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrer_entites function.
0
Attacker Value
Unknown

CVE-2016-3154

Disclosure Date: April 08, 2016 (last updated November 25, 2024)
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
0
Attacker Value
Unknown

CVE-2013-4555

Disclosure Date: November 18, 2013 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in SPIP before 2.1.24 allows remote attackers to hijack the authentication of arbitrary users for requests that logout the user via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-4556

Disclosure Date: November 18, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter.
0
Attacker Value
Unknown

CVE-2013-2118

Disclosure Date: July 09, 2013 (last updated October 05, 2023)
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.
0