Vulnerabilities
Vulnerable Software
Sips:  >> Sips  >> 0.3.0pl1  Security Vulnerabilities
PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) 0.3.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[sipssys] parameter. NOTE: the product's documentation recommends placing the affected file outside of the web root, so the scope of issue is limited to admins who do not, or cannot, follow this recommendation.
CVSS Score
7.5
EPSS Score
0.098
Published
2006-09-13
preferences.php in Simple Internet Publishing System (SIPS) before 0.3.1 allows remote attackers to gain administrative privileges via a linebreak in the "theme" field followed by the Status::admin command, which causes the Status line to be entered into the password file.
CVSS Score
10.0
EPSS Score
0.012
Published
2002-05-29


Contact Us

Shodan ® - All rights reserved