PT-2013-3547 · Spip · Spip
Salvatore Bonaccorso
·
Published
2013-07-09
·
Updated
2013-10-11
·
CVE-2013-2118
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SPIP versions 2.0.x through 2.0.22
SPIP versions 2.1.x through 2.1.21
SPIP versions 3.0.x through 3.0.8
Description
The issue allows remote attackers to gain privileges and take editorial control via vectors related to
ecrire/inc/filtres.php.Recommendations
For SPIP versions 2.0.x through 2.0.22, update to version 2.0.23 or later.
For SPIP versions 2.1.x through 2.1.21, update to version 2.1.22 or later.
For SPIP versions 3.0.x through 3.0.8, update to version 3.0.9 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Spip