Vulnerabilities
Vulnerable Software
Spip:  >> Spip  >> 3.1.1  Security Vulnerabilities
Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.
CVSS Score
6.1
EPSS Score
0.522
Published
2017-01-18
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action.
CVSS Score
7.5
EPSS Score
0.327
Published
2017-01-18
SPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/puce_statut.php involving the `$id` parameter, as demonstrated by a /ecrire/?exec=puce_statut URL.
CVSS Score
6.1
EPSS Score
0.003
Published
2016-12-17
SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/info_plugin.php involving the `$plugin` parameter, as demonstrated by a /ecrire/?exec=info_plugin URL.
CVSS Score
6.1
EPSS Score
0.003
Published
2016-12-17


Contact Us

Shodan ® - All rights reserved