CVE-2013-2118
- EPSS 8.98%
- Veröffentlicht 09.07.2013 17:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.
- EPSS 1.41%
- Veröffentlicht 14.08.2012 22:55:02
- Zuletzt bearbeitet 16.06.2026 23:44:50
Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vectors that are not related to cross-site scripting (XSS), different vulnerabilities than CVE-2012-2151.
CVE-2012-2151
- EPSS 2.38%
- Veröffentlicht 14.08.2012 22:55:01
- Zuletzt bearbeitet 16.06.2026 23:41:05
Multiple cross-site scripting (XSS) vulnerabilities in SPIP 1.9.x before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2009-3041
- EPSS 6.59%
- Veröffentlicht 01.09.2009 18:30:04
- Zuletzt bearbeitet 16.06.2026 23:10:46
SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as explo...
CVE-2008-5813
- EPSS 1.29%
- Veröffentlicht 02.01.2009 18:11:09
- Zuletzt bearbeitet 16.06.2026 23:01:02
SQL injection vulnerability in inc/rubriques.php in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: some of these details are obtained from third pa...
- EPSS 1.53%
- Veröffentlicht 02.01.2009 18:11:09
- Zuletzt bearbeitet 16.06.2026 23:01:02
Multiple unspecified vulnerabilities in SPIP 1.8 before 1.8.3b, 1.9 before 1.9.2g, and 2.0 before 2.0.2 have unknown impact and attack vectors.
CVE-2007-4525
- EPSS 1.6%
- Veröffentlicht 25.08.2007 00:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:15
PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the squelette_cache parameter, a different vector than CVE-2006-1702. NOTE: this issue has been disputed by th...
CVE-2006-1702
- EPSS 2.6%
- Veröffentlicht 11.04.2006 10:02:00
- Zuletzt bearbeitet 16.06.2026 22:23:28
PHP remote file inclusion vulnerability in spip_login.php3 in SPIP 1.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.
CVE-2006-1295
- EPSS 1.18%
- Veröffentlicht 19.03.2006 23:02:00
- Zuletzt bearbeitet 16.06.2026 22:22:23
Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.
CVE-2006-0626
- EPSS 1.32%
- Veröffentlicht 09.02.2006 18:06:00
- Zuletzt bearbeitet 16.06.2026 22:20:57
SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter.