CVE-2006-1702
- EPSS 2.09%
- Veröffentlicht 11.04.2006 10:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
PHP remote file inclusion vulnerability in spip_login.php3 in SPIP 1.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.
CVE-2006-1295
- EPSS 0.43%
- Veröffentlicht 19.03.2006 23:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.
CVE-2006-0626
- EPSS 0.93%
- Veröffentlicht 09.02.2006 18:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter.
CVE-2006-0625
- EPSS 9.68%
- Veröffentlicht 09.02.2006 18:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via ".." sequences in the GLOBALS[type_urls] parameter, which could then be used to execute arbitrary code via re...
- EPSS 0.53%
- Veröffentlicht 02.02.2006 11:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to obtain sensitive information via a direct request to inc-messforum.php3, which reveals the path in an error message.
CVE-2006-0518
- EPSS 10.43%
- Veröffentlicht 02.02.2006 11:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
CVE-2006-0517
- EPSS 3.48%
- Veröffentlicht 02.02.2006 11:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id_forum, (2) id_article, or (3) id_br...
CVE-2005-4494
- EPSS 0.53%
- Veröffentlicht 22.12.2005 11:03:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) spip_login.php3 and (2) spip_pass.php3.