Published: 18/11/2013 Updated: 08/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Security Screen (_core_/securite/ecran_securite.php) prior to 1.1.8 for SPIP, as used in SPIP 3.0.x prior to 3.0.12, allows remote malicious users to execute arbitrary PHP via the connect parameter.

Vulnerable Product Search on Vulmon

spip spip 3.0.0

spip spip 3.0.1

spip spip 3.0.2

spip spip 3.0.3

spip spip 3.0.4

spip spip 3.0.5

spip spip 3.0.6

spip spip 3.0.7

spip spip 3.0.8

spip spip 3.0.9

spip spip 3.0.10

spip spip 3.0.11

Vendor Advisories

Several vulnerabilities have been found in SPIP, a website engine for publishing, resulting in cross-site request forgery on logout, cross-site scripting on author page, and PHP injection For the oldstable distribution (squeeze), these problems have been fixed in version 211-3squeeze7 For the stable distribution (wheezy), these problems have be ...