4.3
CVSSv2

CVE-2013-4556

Published: 18/11/2013 Updated: 08/12/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP prior to 2.1.24 and 3.0.x prior to 3.0.12 allows remote malicious users to inject arbitrary web script or HTML via the url_site parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

spip spip 3.0.3

spip spip 3.0.4

spip spip 2.1.21

spip spip 2.1.20

spip spip 2.1.14

spip spip 2.1.13

spip spip 2.0.7

spip spip 2.0.6

spip spip 2.0.19

spip spip 2.0.18

spip spip 2.0.11

spip spip 3.0.0

spip spip 3.0.7

spip spip 3.0.8

spip spip 2.1.18

spip spip 2.1.17

spip spip 2.1.10

spip spip 2.1.1

spip spip 2.0.3

spip spip 2.0.22

spip spip 2.0.15

spip spip 2.0.14

spip spip 2.1.3

spip spip 2.1.9

spip spip

spip spip 2.0.10

spip spip 2.1.6

spip spip 2.1.4

spip spip 3.0.5

spip spip 3.0.6

spip spip 2.1.2

spip spip 2.1.19

spip spip 2.1.12

spip spip 2.1.11

spip spip 2.0.5

spip spip 2.0.4

spip spip 2.0.17

spip spip 2.0.16

spip spip 2.0.1

spip spip 2.0.0

spip spip 2.1.5

spip spip 2.1.22

spip spip 3.0.1

spip spip 3.0.2

spip spip 3.0.9

spip spip 3.0.10

spip spip 3.0.11

spip spip 2.1.16

spip spip 2.1.15

spip spip 2.0.9

spip spip 2.0.8

spip spip 2.0.21

spip spip 2.0.20

spip spip 2.0.2

spip spip 2.0.13

spip spip 2.0.12

spip spip 2.1.8

spip spip 2.1.7

Vendor Advisories

Several vulnerabilities have been found in SPIP, a website engine for publishing, resulting in cross-site request forgery on logout, cross-site scripting on author page, and PHP injection For the oldstable distribution (squeeze), these problems have been fixed in version 211-3squeeze7 For the stable distribution (wheezy), these problems have be ...