SPIP Security Bypass Vulnerability
BID:60163
Info
SPIP Security Bypass Vulnerability
| Bugtraq ID: | 60163 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2118 |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2013 12:00AM |
| Updated: | May 21 2014 02:33PM |
| Credit: | SPIP |
| Vulnerable: |
SPIP SPIP 2.1.13 SPIP SPIP 2.1.12 SPIP SPIP 2.1 SPIP SPIP 2.0.18 SPIP SPIP 2.0.9 SPIP SPIP 2.0.7 SPIP SPIP 2.0.2 SPIP SPIP 2.1.9 SPIP SPIP 2.1.8 SPIP SPIP 2.1.7 SPIP SPIP 2.1.10 SPIP SPIP 2.0.14 SPIP SPIP 2.0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Discussion
SPIP Security Bypass Vulnerability
SPIP is prone to a remote security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and gain editorial control to the affected application.
Versions prior to SPIP 3.0.9, 2.1.22 and 2.0.23 are vulnerable.
SPIP is prone to a remote security-bypass vulnerability.
Attackers can exploit this issue to bypass certain security restrictions and gain editorial control to the affected application.
Versions prior to SPIP 3.0.9, 2.1.22 and 2.0.23 are vulnerable.
Exploit / POC
SPIP Security Bypass Vulnerability
An attacker can exploit this issue using a browser.
The following exploit is available:
An attacker can exploit this issue using a browser.
The following exploit is available:
Solution / Fix
SPIP Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.