SPIP 'connect' Parameter PHP Code Injection Vulnerability
BID:54292
Info
SPIP 'connect' Parameter PHP Code Injection Vulnerability
| Bugtraq ID: | 54292 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 04 2012 12:00AM |
| Updated: | Aug 30 2013 12:12AM |
| Credit: | Arnault Pachot |
| Vulnerable: |
SPIP SPIP 2.1.13 SPIP SPIP 2.1.12 SPIP SPIP 2.1 SPIP SPIP 2.0.18 SPIP SPIP 2.0.9 SPIP SPIP 2.0.7 SPIP SPIP 2.0.2 SPIP SPIP 2.1.9 SPIP SPIP 2.1.8 SPIP SPIP 2.1.7 SPIP SPIP 2.1.10 SPIP SPIP 2.0.14 SPIP SPIP 2.0 RC1 SPIP SPIP 2.0 |
| Not Vulnerable: | |
Discussion
SPIP 'connect' Parameter PHP Code Injection Vulnerability
SPIP is prone to a remote PHP code-injection vulnerability.
An attacker can exploit this issue to inject and execute arbitrary PHP code in the context of the affected application. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
SPIP versions prior to 2.0.21, 2.1.16, and 3.0.3 are vulnerable.
SPIP is prone to a remote PHP code-injection vulnerability.
An attacker can exploit this issue to inject and execute arbitrary PHP code in the context of the affected application. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
SPIP versions prior to 2.0.21, 2.1.16, and 3.0.3 are vulnerable.
Exploit / POC
SPIP 'connect' Parameter PHP Code Injection Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
SPIP 'connect' Parameter PHP Code Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.