PT-2006-1581 · Spip · Spip

Benot Sklnard

+3

·

Published

2006-02-02

·

Updated

2018-10-19

·

CVE-2006-0517

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SPIP versions 1.8.2-e and earlier SPIP versions 1.9 Alpha 2 and earlier
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the id forum, id article, or id breve parameters to "forum.php3", unspecified vectors related to session handling, and when posting petitions.
Recommendations For SPIP versions 1.8.2-e and earlier, avoid using the id forum, id article, and id breve parameters in the "forum.php3" endpoint until the issue is resolved. For SPIP versions 1.9 Alpha 2 and earlier, consider restricting access to session handling and petition posting functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0517

Affected Products

Spip