PT-2016-5385 · Spip · Spip
G0Uz
+1
·
Publicado
2016-03-16
·
Atualizado
2016-04-14
·
CVE-2016-3153
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SPIP versions 2.x through 2.1.18
SPIP versions 3.0.x through 3.0.21
SPIP versions 3.1.x through 3.1.0
Description
The issue allows remote attackers to execute arbitrary PHP code by adding content, related to the
filtrer entites function.Recommendations
For SPIP versions 2.x through 2.1.18, update to version 2.1.19 or later.
For SPIP versions 3.0.x through 3.0.21, update to version 3.0.22 or later.
For SPIP versions 3.1.x through 3.1.0, update to version 3.1.1 or later.
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Spip