CVE-2017-15736
https://notcve.org/view.php?id=CVE-2017-15736
Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web script or HTML via a crafted string, as demonstrated by a PGP field, related to prive/objets/contenu/auteur.html and ecrire/inc/texte_mini.php. Vulnerabilidad de Cross-Site Scripting (XSS) (persistente) en SPIP en versiones anteriores a la 3.1.7 permite que atacantes remotos inyecten scripts web o HTML arbitrarios mediante una cadena manipulada, tal y como demuestra un campo PGP, relacionado con prive/objets/contenu/auteur.html y ecrire/inc/texte_mini.php. • https://core.spip.net/projects/spip/repository/revisions/23701 https://usn.ubuntu.com/4536-1 https://www.debian.org/security/2018/dsa-4228 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2017-9736
https://notcve.org/view.php?id=CVE-2017-9736
SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution. SPIP en versiones 3.1.x anteriores a la 3.1.6 y versiones 3.2.x anteriores a la Beta 3 no elimina los metacaracteres shell del campo host, lo que permite que un atacante remoto provoque la ejecución remota de código. • http://www.debian.org/security/2017/dsa-3890 https://contrib.spip.net/CRITICAL-security-update-SPIP-3-1-6-and-SPIP-3-2-Beta https://core.spip.net/projects/spip/repository/revisions/23593 https://core.spip.net/projects/spip/repository/revisions/23594 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •