605
VMScore

CVE-2013-4555

Published: 18/11/2013 Updated: 08/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in SPIP prior to 2.1.24 allows remote malicious users to hijack the authentication of arbitrary users for requests that logout the user via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

spip spip 2.0.0

spip spip 2.0.1

spip spip 2.0.2

spip spip 2.0.3

spip spip 2.0.4

spip spip 2.0.5

spip spip 2.0.6

spip spip 2.0.7

spip spip 2.0.8

spip spip 2.0.9

spip spip 2.0.10

spip spip 2.0.11

spip spip 2.0.12

spip spip 2.0.13

spip spip 2.0.14

spip spip 2.0.15

spip spip 2.0.16

spip spip 2.0.17

spip spip 2.0.18

spip spip 2.0.19

spip spip 2.0.20

spip spip 2.0.21

spip spip 2.0.22

spip spip 2.1.1

spip spip 2.1.2

spip spip 2.1.3

spip spip 2.1.4

spip spip 2.1.5

spip spip 2.1.6

spip spip 2.1.7

spip spip 2.1.8

spip spip 2.1.9

spip spip 2.1.10

spip spip 2.1.11

spip spip 2.1.12

spip spip 2.1.13

spip spip 2.1.14

spip spip 2.1.15

spip spip 2.1.16

spip spip 2.1.17

spip spip 2.1.18

spip spip 2.1.19

spip spip 2.1.20

spip spip 2.1.21

spip spip 2.1.22

spip spip

Vendor Advisories

Several vulnerabilities have been found in SPIP, a website engine for publishing, resulting in cross-site request forgery on logout, cross-site scripting on author page, and PHP injection For the oldstable distribution (squeeze), these problems have been fixed in version 211-3squeeze7 For the stable distribution (wheezy), these problems have be ...