Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SPIP数据库备份请求绕过认证漏洞
Vulnerability Description
SPIP是一套免费的基于Web的内容发布系统。该系统主要用于在线协作。 SPIP没有正确地限制对ecrire/exec/install.php和ecrire/index.php的访问,远程攻击者可以通过提交恶意的数据库备份请求执行各种非授权操作,如获得管理员的口令哈希。
CVSS Information
N/A
Vulnerability Type
N/A