7.5

CVE-2009-3041

Exploit

SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SpipSpip Version1.9
SpipSpip Version1.9 Updatealpha2
SpipSpip Version1.9.1
SpipSpip Version1.9.2c
SpipSpip Version1.9.2d
SpipSpip Version1.9.2g
SpipSpip Version1.9.2h
SpipSpip Version1.9.alpha1
SpipSpip Version2.0 Updaterc1
SpipSpip Version2.0.0
SpipSpip Version2.0.1
SpipSpip Version2.0.2
SpipSpip Version2.0.3
SpipSpip Version2.0.4
SpipSpip Version2.0.5
SpipSpip Version2.0.6
SpipSpip Version2.0.7
SpipSpip Version2.0.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.84% 0.87
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P