Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2022-37155
RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.05
EPSS Ranking
89.2%
CVSS Severity
CVSS v3 Score
8.8
References
https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-1-5-SPIP-4-0-8-et-SPIP-3-2-16.html
https://github.com/Abyss-W4tcher/ab4yss-wr4iteups/blob/ffa980faa9e3598d49d6fb7def4f7a67cfb5f427/SPIP%20-%20Pentest/SPIP%204.1.2/SPIP_4.1.2_AUTH_RCE/SPIP_4.1.2_AUTH_RCE_Abyss_Watcher_12_07_22.md
https://pastebin.com/ZH7CPc8X
https://spawnzii.github.io/posts/2022/07/how-we-have-pwned-root-me-in-2022/
https://blog.spip.net/Mise-a-jour-critique-de-securite-sortie-de-SPIP-4-1-5-SPIP-4-0-8-et-SPIP-3-2-16.html
https://github.com/Abyss-W4tcher/ab4yss-wr4iteups/blob/ffa980faa9e3598d49d6fb7def4f7a67cfb5f427/SPIP%20-%20Pentest/SPIP%204.1.2/SPIP_4.1.2_AUTH_RCE/SPIP_4.1.2_AUTH_RCE_Abyss_Watcher_12_07_22.md
https://pastebin.com/ZH7CPc8X
https://spawnzii.github.io/posts/2022/07/how-we-have-pwned-root-me-in-2022/
Products affected by CVE-2022-37155
Spip
»
Spip
»
Version:
3.1.13
cpe:2.3:a:spip:spip:3.1.13
Spip
»
Spip
»
Version:
3.1.14
cpe:2.3:a:spip:spip:3.1.14
Spip
»
Spip
»
Version:
3.1.15
cpe:2.3:a:spip:spip:3.1.15
Spip
»
Spip
»
Version:
3.2
cpe:2.3:a:spip:spip:3.2
Spip
»
Spip
»
Version:
3.2.0
cpe:2.3:a:spip:spip:3.2.0
Spip
»
Spip
»
Version:
3.2.1
cpe:2.3:a:spip:spip:3.2.1
Spip
»
Spip
»
Version:
3.2.10
cpe:2.3:a:spip:spip:3.2.10
Spip
»
Spip
»
Version:
3.2.11
cpe:2.3:a:spip:spip:3.2.11
Spip
»
Spip
»
Version:
3.2.12
cpe:2.3:a:spip:spip:3.2.12
Spip
»
Spip
»
Version:
3.2.13
cpe:2.3:a:spip:spip:3.2.13
Spip
»
Spip
»
Version:
3.2.14
cpe:2.3:a:spip:spip:3.2.14
Spip
»
Spip
»
Version:
3.2.15
cpe:2.3:a:spip:spip:3.2.15
Spip
»
Spip
»
Version:
3.2.16
cpe:2.3:a:spip:spip:3.2.16
Spip
»
Spip
»
Version:
3.2.17
cpe:2.3:a:spip:spip:3.2.17
Spip
»
Spip
»
Version:
3.2.18
cpe:2.3:a:spip:spip:3.2.18
Spip
»
Spip
»
Version:
3.2.19
cpe:2.3:a:spip:spip:3.2.19
Spip
»
Spip
»
Version:
3.2.2
cpe:2.3:a:spip:spip:3.2.2
Spip
»
Spip
»
Version:
3.2.3
cpe:2.3:a:spip:spip:3.2.3
Spip
»
Spip
»
Version:
3.2.4
cpe:2.3:a:spip:spip:3.2.4
Spip
»
Spip
»
Version:
3.2.5
cpe:2.3:a:spip:spip:3.2.5
Spip
»
Spip
»
Version:
3.2.6
cpe:2.3:a:spip:spip:3.2.6
Spip
»
Spip
»
Version:
3.2.7
cpe:2.3:a:spip:spip:3.2.7
Spip
»
Spip
»
Version:
3.2.8
cpe:2.3:a:spip:spip:3.2.8
Spip
»
Spip
»
Version:
3.2.9
cpe:2.3:a:spip:spip:3.2.9
Spip
»
Spip
»
Version:
4.0.0
cpe:2.3:a:spip:spip:4.0.0
Spip
»
Spip
»
Version:
4.0.1
cpe:2.3:a:spip:spip:4.0.1
Spip
»
Spip
»
Version:
4.0.10
cpe:2.3:a:spip:spip:4.0.10
Spip
»
Spip
»
Version:
4.0.11
cpe:2.3:a:spip:spip:4.0.11
Spip
»
Spip
»
Version:
4.0.2
cpe:2.3:a:spip:spip:4.0.2
Spip
»
Spip
»
Version:
4.0.3
cpe:2.3:a:spip:spip:4.0.3
Spip
»
Spip
»
Version:
4.0.4
cpe:2.3:a:spip:spip:4.0.4
Spip
»
Spip
»
Version:
4.0.5
cpe:2.3:a:spip:spip:4.0.5
Spip
»
Spip
»
Version:
4.0.6
cpe:2.3:a:spip:spip:4.0.6
Spip
»
Spip
»
Version:
4.0.7
cpe:2.3:a:spip:spip:4.0.7
Spip
»
Spip
»
Version:
4.0.8
cpe:2.3:a:spip:spip:4.0.8
Spip
»
Spip
»
Version:
4.0.9
cpe:2.3:a:spip:spip:4.0.9
Spip
»
Spip
»
Version:
4.1.0
cpe:2.3:a:spip:spip:4.1.0
Spip
»
Spip
»
Version:
4.1.1
cpe:2.3:a:spip:spip:4.1.1
Spip
»
Spip
»
Version:
4.1.2
cpe:2.3:a:spip:spip:4.1.2
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved