Vulnerabilities
Vulnerable Software
Spip:  >> Spip  >> 4.2.7  Security Vulnerabilities
SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.
CVSS Score
9.8
EPSS Score
0.9
Published
2024-09-06
SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.
CVSS Score
6.1
EPSS Score
0.01
Published
2024-01-19


Contact Us

Shodan ® - All rights reserved