Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2009-3041

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SPIP是一套免费的基于Web的内容发布系统。该系统主要用于在线协作。 SPIP没有正确地限制对ecrire/exec/install.php和ecrire/index.php的访问,远程攻击者可以通过提交恶意的数据库备份请求执行各种非授权操作,如获得管理员的口令哈希。

AI Predicted 7.5 Difficulty: Easy EPSS 6.59% · P94

Public Exploits 1

ExploitDB · 1 EDB-9448 [webapps]
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2009-3041

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
SPIP数据库备份请求绕过认证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SPIP是一套免费的基于Web的内容发布系统。该系统主要用于在线协作。 SPIP没有正确地限制对ecrire/exec/install.php和ecrire/index.php的访问,远程攻击者可以通过提交恶意的数据库备份请求执行各种非授权操作,如获得管理员的口令哈希。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2009-3041

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-3041

请登录查看更多情报信息。

Vendor Advisories for CVE-2009-3041 (4)

Other References for CVE-2009-3041 (1)

Same Patch Batch · n/a · 2009-09-01 · 26 CVEs total

CVE-2008-7142 cPanel 磁盘使用模块绝对路径游历漏洞
CVE-2009-3038 RIM BlackBerry Desktop Manager 拒绝服务漏洞
CVE-2009-3037 Autonomy KeyView软件包XSL文件 远程缓冲区溢出漏洞
CVE-2008-7152 Simon_Rycroft SID 'dir'参数远程文件包含漏洞
CVE-2008-7151 Gurpartap_Singh Drupal Live模块跨站请求伪造漏洞
CVE-2008-7150 Ber_Kessels Drupal Refine by Taxonomy模块跨站脚本攻击漏洞
CVE-2008-7149 AgileWiki 未明漏洞
CVE-2008-7148 synfig Animation studio 未明漏洞
CVE-2008-7147 IntraLearn 跨站脚本攻击漏洞
CVE-2008-7146 IntraLearn 敏感信息泄露漏洞
CVE-2008-7145 CoronaMatrix phpAddressBook 'index.php' SQL注入漏洞
CVE-2008-7144 rarlab winrar 多个未明漏洞
CVE-2008-7143 phpbb 信息泄露漏洞
CVE-2009-3040 OCS Inventory NG download.php和group_show.php SQL注入漏洞
CVE-2008-7141 Alexphpteam lex Poll 'setup.php'跨站脚本攻击漏洞
CVE-2008-7140 Alexguestbook lex Guestbook多个跨站脚本攻击漏洞
CVE-2008-7139 Eye-Fi 'WS-Proxy'多个跨站请求伪造漏洞
CVE-2008-7138 Eye-Fi管理器密码泄露漏洞
CVE-2008-7137 Eye-Fi 'WS-Proxy'拒绝服务漏洞
CVE-2008-7136 icq_toolbar 'toolbaru.dll' 多个远程拒绝服务漏洞

Showing top 20 of 26 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2009-3041

No comments yet


Leave a comment