Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.20978
Categoría:Web application abuses
Título:SPIP < 1.8.2-g SQL Injection and XSS Flaws
Resumen:The remote web server has a PHP application that is affected by multiple flaws.
Descripción:Summary:
The remote web server has a PHP application that is affected by multiple flaws.

Vulnerability Insight:
The remote version of this software is prone to SQL injection and cross-site
scripting attacks. An attacker could send a specially crafted URL to modify SQL requests, for example, to obtain
the admin password hash, or execute malicious script code on the remote system.

Solution:
Upgrade to SPIP version 1.8.2-g or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2006-0517
BugTraq ID: 16458
http://www.securityfocus.com/bid/16458
BugTraq ID: 24397
http://www.securityfocus.com/bid/24397
Bugtraq: 20060131 ZRCSA-200601: SPIP - Multiple Vulnerabilities (Google Search)
http://www.securityfocus.com/archive/1/423655/100/0/threaded
http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0990.html
http://www.zone-h.org/en/advisories/read/id=8650/
http://www.osvdb.org/22844
http://www.osvdb.org/22845
http://www.osvdb.org/22848
http://securitytracker.com/id?1015556
http://secunia.com/advisories/18676
http://securityreason.com/securityalert/395
http://www.vupen.com/english/advisories/2006/0398
XForce ISS Database: spip-forum-sql-injection(24397)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24397
Common Vulnerability Exposure (CVE) ID: CVE-2006-0518
BugTraq ID: 16461
http://www.securityfocus.com/bid/16461
http://www.osvdb.org/22849
XForce ISS Database: spip-index-xss(24401)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24401
Common Vulnerability Exposure (CVE) ID: CVE-2006-0519
XForce ISS Database: spip-incmessforum-path-disclosure(24399)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24399
CopyrightCopyright (C) 2006 David Maciejak

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.