CVE-2013-7303
https://notcve.org/view.php?id=CVE-2013-7303
Multiple cross-site scripting (XSS) vulnerabilities in (1) squelettes-dist/formulaires/inscription.php and (2) prive/forms/editer_auteur.php in SPIP before 2.1.25 and 3.0.x before 3.0.13 allow remote attackers to inject arbitrary web script or HTML via the author name field. Múltiples vulnerabilidades de XSS en (1) squelettes-dist/formulaires/inscription.php y (2) prive/forms/editer_auteur.php de SPIP anterior a la versión 2.1.25 y 3.0.x anterior a 3.0.13 permite a atacantes remotos inyectar script Web o HTML arbitrario a través del campo de nombre de autor. • http://core.spip.org/projects/spip/repository/revisions/20902 http://seclists.org/oss-sec/2014/q1/123 http://seclists.org/oss-sec/2014/q1/128 http://secunia.com/advisories/56381 http://www.securitytracker.com/id/1029703 http://www.spip.net/fr_article5648.html http://www.spip.net/fr_article5665.html http://zone.spip.org/trac/spip-zone/changeset/77768 https://exchange.xforce.ibmcloud.com/vulnerabilities/90643 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2013-4555
https://notcve.org/view.php?id=CVE-2013-4555
Cross-site request forgery (CSRF) vulnerability in ecrire/action/logout.php in SPIP before 2.1.24 allows remote attackers to hijack the authentication of arbitrary users for requests that logout the user via unspecified vectors. Vulnerabilidad de CSRF en ecrire/action/logout.php de SPIP anterior a la versión 2.1.24 permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios por solicitudes que cierren la sesión del usuario a través de vectores sin especificar. • http://core.spip.org/projects/spip/repository/revisions/20874 http://secunia.com/advisories/55551 http://www.openwall.com/lists/oss-security/2013/11/10/4 http://www.securitytracker.com/id/1029317 http://www.spip.net/fr_article5646.html https://www.debian.org/security/2013/dsa-2794 • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2013-4556
https://notcve.org/view.php?id=CVE-2013-4556
Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter. Vulnerabilidad de XSS en la página de autor (prive/formulaires/editer_auteur.php) de SPIP anterior a la versión 2.1.24 y 3.0.x anterior a 3.0.12 permite a atacantes remotos inyectar script web o HTML arbitrario a través del parámetro url_site. • http://core.spip.org/projects/spip/repository/revisions/20879 http://core.spip.org/projects/spip/repository/revisions/20880 http://secunia.com/advisories/55551 http://www.openwall.com/lists/oss-security/2013/11/10/4 http://www.securitytracker.com/id/1029317 http://www.spip.net/fr_article5646.html http://www.spip.net/fr_article5648.html https://www.debian.org/security/2013/dsa-2794 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2007-4525
https://notcve.org/view.php?id=CVE-2007-4525
PHP remote file inclusion vulnerability in inc-calcul.php3 in SPIP 1.7.2 allows remote attackers to execute arbitrary PHP code via a URL in the squelette_cache parameter, a different vector than CVE-2006-1702. NOTE: this issue has been disputed by third party researchers, stating that the squelette_cache variable is initialized before use, and is only used within the scope of a function ** EN DISPUTA ** Vulnerabilidad de inclusión remota de archivo en PHP en inc-calcul.php3 de SPIP versión 1.7.2 permite a atacantes remotos ejecutar código PHP de su elección mediante un URL en el parámetro squelette_cache parameter, vector distinto de CVE-2006-1702. NOTA: esta característica ha sido cuestionada por investigadores de terceros, que indica que la variable squelette_cache es inicializada antes de su uso, y sólo se utiliza en el ámbito de una función. • http://securityreason.com/securityalert/3056 http://www.securityfocus.com/archive/1/477423/100/0/threaded http://www.securityfocus.com/archive/1/477728/100/0/threaded http://www.securityfocus.com/bid/25416 https://exchange.xforce.ibmcloud.com/vulnerabilities/36218 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2006-0519
https://notcve.org/view.php?id=CVE-2006-0519
SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to obtain sensitive information via a direct request to inc-messforum.php3, which reveals the path in an error message. • http://secunia.com/advisories/18676 http://www.vupen.com/english/advisories/2006/0398 http://www.zone-h.org/en/advisories/read/id=8650 https://exchange.xforce.ibmcloud.com/vulnerabilities/24399 •