# N/A
## 漏洞概述
SPIP版本早于4.2.1的远程代码执行漏洞,源于公有区域表单值中的序列化处理不当。
## 影响版本
- 早于4.2.1的所有版本
## 漏洞细节
在SPIP版本4.2.1之前的版本中,由于公有区域中的表单值序列化处理不当,攻击者可以通过操纵这些表单值执行远程代码。
## 影响
- 受影响版本包括低于4.2.1的所有版本。已修复版本为3.2.18、4.0.10、4.1.8及4.2.1。
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1. | https://github.com/nuts7/CVE-2023-27372 | POC详情 |
| 2 | SPIP Vulnerability Scanner - CVE-2023-27372 Detector | https://github.com/Chocapikk/CVE-2023-27372 | POC详情 |
| 3 | This is a PoC for CVE-2023-27372 which spawns a fully interactive shell. | https://github.com/0SPwn/CVE-2023-27372-PoC | POC详情 |
| 4 | CVE-2023-27372-SPIP-CMS-Bypass | https://github.com/izzz0/CVE-2023-27372-POC | POC详情 |
| 5 | Perform With Mass Remote Code Execution In SPIP Version (4.2.1) | https://github.com/ThatNotEasy/CVE-2023-27372 | POC详情 |
| 6 | This is a PoC for CVE-2023-27372 and spawns a fully interactive shell. | https://github.com/redboltsec/CVE-2023-27372-PoC | POC详情 |
| 7 | spip | https://github.com/Jhonsonwannaa/CVE-2023-27372 | POC详情 |
| 8 | None | https://github.com/1amthebest1/CVE-2023-27372 | POC详情 |
| 9 | None | https://github.com/inviewp/CVE-2023-27372 | POC详情 |
| 10 | spip | https://github.com/dream434/CVE-2023-27372 | POC详情 |
| 11 | SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-27372.yaml | POC详情 |
| 12 | SPIP CVE-2023-27372 Unauthenticated RCE Exploit (Web Shell Upload) | https://github.com/1Ronkkeli/spip-cve-2023-27372-rce | POC详情 |
| 13 | None | https://github.com/G01d3nW01f/cve-2023-27372 | POC详情 |
%u What i do not understood is if truth be told how you are now not actually much more well-liked than you might be right now. You're so intelligent. You realize therefore considerably with regards to this matter, produced me for my part believe it from so many varied angles. Its like women and men aren't fascinated except it is one thing to accomplish with Woman gaga! Your own stuffs outstanding. All the time deal with it up!https://hypestat.com/info/yst-group.com%2Fbitrix%2Fclick.php%3Fgoto%3Dhttps%3A%2F%2Fste-b2b.agency%2F
%u Wow, awesome weblog structure! How long have you been running a blog for? you made blogging glance easy. The total glance of your website is fantastic, as well as the content! https://ste-b2b.agency/
%u That is a good tip particularly to those new to the blogosphere. Brief but very accurate info… Thank you for sharing this one. A must read article!http://games.lynms.edu.hk/jump.php?sid=1594&url=https://ste-b2b.agency/
%u I've been browsing on-line more than 3 hours today, but I never discovered any interesting article like yours. It's beautiful worth enough for me. In my view, if all web owners and bloggers made good content as you probably did, the web shall be much more useful than ever before.http://www.nnov.org/common/redir.php?https://campus.tdea.edu.co/cas/logout?url=https%3A%2F%2Fste-b2b.agency
%u This is the right blog for everyone who would like to find out about this topic. You realize a whole lot its almost tough to argue with you (not that I personally would want to…HaHa). You certainly put a brand new spin on a topic that has been written about for a long time. Wonderful stuff, just great!https://www.google.kg/url?sa=t&url=https%3A%2F%2F65.staikudrik.com%2Findex%2Fd1%3Fdiff%3D0%26utm_clickid%3Duskkokskw44sooos%26aurl%3Dhttps%3A%2F%2Fste-b2b.agency%2F
https://top11ng.com Valuable info. Lucky me I found your web site by accident, and I'm shocked why this coincidence did not took place earlier! I bookmarked it.https://top11ng.com
%u If you wish for to take a good deal from this piece of writing then you have to apply such techniques to your won weblog.https://o-smolensk.ru/go?a:aHR0cHM6Ly9zdGUtYjJiLmFnZW5jeS8
%u Its like you read my mind! You seem to know a lot about this, like you wrote the book in it or something. I think that you can do with some pics to drive the message home a little bit, but other than that, this is great blog. An excellent read. I'll certainly be back.http://www.climatvk.ru/objects/biznes-tsentr-po-ulchapaeva-14a/action.redirect/url/aHR0cHM6Ly9zdGUtYjJiLmFnZW5jeS8
%u Yes! Finally something about steb2b.agency.http://sky-blue.hexat.com/r.php?u=//thinkexist.com%2Fcommon%2Fhowtolink.asp%3Fdir%3Dhttps%3A%2F%2Fste-b2b.agency%2F
%u I blog often and I truly thank you for your content. The article has really peaked my interest. I am going to book mark your website and keep checking for new information about once per week. I opted in for your RSS feed too.https://praga-praha.ru/go?https://ste-b2b.agency/
%u I was suggested this web site by my cousin. I am not sure whether this post is written by him as no one else know such detailed about my problem. You are incredible! Thanks!https://barclay.ru/include/main/script.php?img=/include/main/img/%d0%9b%d0%95%d0%93%d0%9a%d0%9e%d0%92%d0%9e%d0%99%20%d0%90%d0%92%d0%a2%d0%9e%d0%a1%d0%95%d0%a0%d0%92%d0%98%d0%a1/%d0%90%d0%bc%d0%be%d1%80%d1%82%d0%b8%d0%b7%d0%b0%d1%82%d0%be%d1%80%d0%bd%d1%8b%d0%b5%20%d0%9b%d0%95%d0%93%d0%9a%d0%9e%d0%92%d0%9e%d0%99.jpg&url=https%3A%2F%2Fsyclub24.ru%2Fproxy.php%3Flink%3Dhttps%3A%2F%2Fste-b2b.agency%2F
%u Thanks for finally talking about >漏洞信息(CVE-2023-27372) - by 漏洞平台 <Liked it!https://images.google.com.iq/url?q=https://ste-b2b.agency/
%u Quality articles is the main to attract the visitors to go to see the web page, that's what this web site is providing.https://ste-b2b.agency/
%u I read this post completely on the topic of the comparison of latest and earlier technologies, it's remarkable article.https://ste-b2b.agency/
%u I've been browsing online more than 2 hours today, yet I never found any interesting article like yours. It's pretty worth enough for me. In my opinion, if all web owners and bloggers made good content as you did, the web will be a lot more useful than ever before.https://ste-b2b.agency/
%u Hello there! Do you know if they make any plugins to protect against hackers? I'm kinda paranoid about losing everything I've worked hard on. Any recommendations?https://ste-b2b.agency/
%u Hello to all, because I am really keen of reading this website's post to be updated regularly. It contains pleasant material.https://ste-b2b.agency/
%u I blog often and I really appreciate your information. Your article has really peaked my interest. I will bookmark your site and keep checking for new details about once a week. I opted in for your Feed as well.https://ste-b2b.agency/
%u I really love your website.. Pleasant colors & theme. Did you build this amazing site yourself? Please reply back as I'm hoping to create my very own site and would like to learn where you got this from or what the theme is called. Kudos!https://ste-b2b.agency/
%u You actually make it appear so easy together with your presentation but I find this topic to be actually something that I think I'd never understand. It seems too complex and extremely wide for me. I'm having a look forward on your subsequent publish, I will attempt to get the cling of it!https://ste-b2b.agency/
%u What's up, I check your blogs like every week. Your writing style is witty, keep up the good work!https://ste-b2b.agency/
%u I loved as much as you'll receive carried out right here. The sketch is tasteful, your authored material stylish. nonetheless, you command get got an shakiness over that you wish be delivering the following. unwell unquestionably come more formerly again since exactly the same nearly a lot often inside case you shield this hike.https://ste-b2b.agency/
%u If you are going for most excellent contents like me, simply pay a quick visit this web page every day because it gives feature contents, thankshttps://ste-b2b.agency/
%u Ahaa, its good discussion about this piece of writing here at this weblog, I have read all that, so now me also commenting here.https://ste-b2b.agency/
%u When I initially left a comment I appear to have clicked the -Notify me when new comments are added- checkbox and now whenever a comment is added I get 4 emails with the exact same comment. Perhaps there is a means you are able to remove me from that service? Thanks a lot!https://ste-b2b.agency/
%u Keep on writing, great job!https://ste-b2b.agency/
%u When I originally commented I clicked the "Notify me when new comments are added" checkbox and now each time a comment is added I get four emails with the same comment. Is there any way you can remove people from that service? Cheers!https://ste-b2b.agency/
मैंने अभी खेला E2BET आधिकारिक साइट, और देखें: https://e2betportal.com/in/
%u Excellent beat ! I would like to apprentice whilst you amend your web site, how could i subscribe for a weblog website? The account aided me a applicable deal. I were tiny bit familiar of this your broadcast offered vivid transparent concepthttps://pt.xhamster.desi/exit.php?url=https%3A%2F%2Ftourzwei.radblogger.net%2Fredirect.php%3Furl%3Dste-b2b.agency
%u Admiring the hard work you put into your site and detailed information you offer. It's good to come across a blog every once in a while that isn't the same out of date rehashed material. Excellent read! I've saved your site and I'm adding your RSS feeds to my Google account.https://catalog.toledo24.ru/bitrix/rk.php?goto=https://ste-b2b.agency/
%u Magnificent beat ! I would like to apprentice while you amend your site, how could i subscribe for a blog web site? The account helped me a acceptable deal. I had been a little bit acquainted of this your broadcast offered bright clear ideahttps://xn----7sbgimwvecb.xn--p1ai/bitrix/redirect.php?goto=https://telemarket24.ru/bitrix/click.php?goto=https://ste-b2b.agency/
%u Hello Dear, are you actually visiting this website on a regular basis, if so then you will absolutely get good knowledge.https://www.wbc.poznan.pl/dlibra/login?refUrl=aHR0cHM6Ly9jbGllbnRzMS5nb29nbGUuZnIvdXJsP3JjdD1qJnNhPXQmc291cmNlPXdlYiZ1cmw9aHR0cHM6Ly9zdGUtYjJiLmFnZW5jeS8
%u Hello, I check your blog regularly. Your writing style is witty, keep it up!https://www.srtconnection.com/proxy.php?link=https://ste-b2b.agency/
4M Dental Implant Center San Diego 5643 Copley Ꭰr ste 210, San Diego, ⅭA 92111, United Stаteѕ 18582567711 Implant bridges
Reftesh Renovation Southwest Charlotte 1251 Arrow Piine Ɗr c121, Charlotte, NC 28273, United Statеs +19803517882 Extra for space adfditions home
This is a topic that's close to my heart... Cheers! Where are your contact details though? https://paito.click/
%u Excellent website you have here but I was wondering if you knew of any message boards that cover the same topics talked about in this article? I'd really love to be a part of group where I can get advice from other experienced people that share the same interest. If you have any recommendations, please let me know. Thanks a lot!http://errwsp.o2active.cz/?code=i503c&url=https://hiddenwiki.co/index.php?title=Wondering_Methods_To_Make_Your_B2b_Marketing_Rock_Read_This
%u I think this is among the so much significant info for me. And i'm happy reading your article. However should commentary on some normal things, The web site taste is perfect, the articles is actually nice : D. Good activity, cheershttp://www.halleyweb.com/c068031/mc/mc_gridev_messi.php?x=33a1b168aeca3418539ea8e5ae6d2fd5&servizio=&bck=https%3A%2F%2Fwww.google.co.ke%2Furl%3Fq%3Dhttps%3A%2F%2Fste-b2b.agency%2F
%u Hello, I think your blog might be having browser compatibility issues. When I look at your website in Ie, it looks fine but when opening in Internet Explorer, it has some overlapping. I just wanted to give you a quick heads up! Other then that, great blog!https://clients1.google.com.ar/url?q=https://vgi2.volsu.ru/bitrix/redirect.php?goto=https://ste-b2b.agency/
%u Excellent weblog here! Additionally your site a lot up fast! What host are you the use of? Can I get your affiliate link in your host? I desire my site loaded up as fast as yours lolhttps://lumeron.ru/bitrix/redirect.php?goto=https%3A%2F%2Fste-b2b.agency
%u Howdy, i read your blog from time to time and i own a similar one and i was just curious if you get a lot of spam responses? If so how do you reduce it, any plugin or anything you can recommend? I get so much lately it's driving me mad so any support is very much appreciated.http://weldproltd.com/?URL=https://ste-b2b.agency/
%u I'm really enjoying the design and layout of your website. It's a very easy on the eyes which makes it much more pleasant for me to come here and visit more often. Did you hire out a designer to create your theme? Exceptional work!https://wetm.ru/bitrix/redirect.php?goto=https://fh-haustechnik.at/?URL=https://ste-b2b.agency/
%u I like it whenever people get together and share opinions. Great site, continue the good work!http://toolbarqueries.google.com.pa/url?q=https://rentry.co/78524-answers-about-search-engine-optimization
%u Hey outstanding blog! Does running a blog similar to this take a massive amount work? I have no expertise in computer programming however I had been hoping to start my own blog in the near future. Anyhow, should you have any suggestions or tips for new blog owners please share. I know this is off topic however I just had to ask. Thank you!https://5.41.gregorinius.com/index/d1?diff=0&source=og&campaign=4397&content=&clickid=hrx9nw9psafm4g9v&aurl=http%3A%2F%2Fste-b2b.agency&utm_source=ogdd&utm_campaign=26607&utm_content=&utm_clickid=j4g880ow8gwcwg84&title=joellemonetcream99964&url=https%3A%2F%2Fjoellemonet.com%2F&email=jettmcguigan%40web.de++skin+color+as+this+will+help+to+your+skin+to+become+richer+&smoother__For_greasy_skin_around_the_globe_beneficial%2C_since_it_is_soaks_oil_for_till_10_hours__Give_a_gentle_massage_with_the_face_using_moisturizer_and_apply_it_on_your_neck%2C_to_see_the_perfect_image_%3Cbr%3E%0D%0A%3Cbr%3E%0D%0A%0D%0A%3Cbr%3E%0D%0A%3Cbr%3E%0D%0A%0D%0AWell%2C_even_if_essential_oils_and_wrinkles_are_strongly_connected%2C_that_doesn%27t_mean_that_all_oils_work_the_same_and_how_the_result_always_be_what_you_expect__There_are_major_differences_between_oil_types_and_you_will_know_exactly_what_you_need_it_if_you_must_cure_your_wrinkles_%3Cbr%3E%0D%0A%3Cbr%3E%0D%0A%0D%0A%3Cbr%3E%0D%0A%3Cbr%3E%0D%0A%0D%0Ahealthline_com_-_https%3A%2F%2Fwww_healthline_com%2Fhealth%2Fhow-to-get-rid-of-frown-lines_For_fantastic_cutting_back_on_the_degree_of_food_consume_at_one_setting_will_help%2C_just_be_sure_to_switch_to_five_small_meals_each_working__For_many_men_and_women%2C_they_you_should_be_affected_by_acid_reflux_when_they_eat_a_lot_food__You_can_to_still_end_up_eating_the_very_same_amount_of_food_to_perform_just_divide_it_up_throughout_the_day%2C_instead_of_eating_everything_in_2_or_3_meals_%0D%0A---------------------------1692248488%0D%0AContent-Disposition%3A_form-data%3B_name=%22field_pays%5Bvalue%5D%22%0D%0A%0D%0ABahrain%0D%0A---------------------------1692248488%0D%0AContent-Disposition%3A+form-data%3B+name%3D%22changed%22%0D%0A%0D%0A%0D%0A---------------------------1692248488%0D%0AContent-Disposition%3A+form-data%3B+nam&pushMode=popup%3B
%u Nice post. I was checking continuously this blog and I am inspired! Extremely useful info specifically the last phase :) I take care of such info a lot. I used to be looking for this particular info for a long time. Thanks and good luck. http://aquarium-vl.ru/forum/go.php?url=aHR0cHM6Ly9lbGVjdHJpY2FscmVwYWlyc2d1aWRlLnNpdGV5Lm1lL3MvY2RuLz9zdGUtYjJiLmFnZW5jeQ
%u You should take part in a contest for one of the best blogs on the net. I'm going to highly recommend this web site!http://ablrus.ru/bitrix/redirect.php?goto=https://api.ppzy.com/jump/aHR0cHM6Ly9zdGUtYjJiLmFnZW5jeS8=
%u This piece of writing presents clear idea in favor of the new people of blogging, that actually how to do blogging and site-building.http://dainelee.net/cgi-bin/pldbbs/pldbbs.cgi?p=1&review=0783&sgroup=1&goto=www.google.pl%2Furl%3Fq%3Dhttps%3A%2F%2Fwww.fujigoko.tv%2FlinkGo2.cgi%3Flink%3Dhttps%3A%2F%2Frentry.co%2F19293-seo-companies-in-mohali
%u Wow, this article is fastidious, my sister is analyzing these kinds of things, so I am going to tell her.https://10.falugyw.com/index/d1?diff=0&utm_source=ogdd&utm_campaign=26607&utm_content=&utm_clickid=lwk48swgwg4s4k08&aurl=https://malenkymirroz.ru/bitrix/redirect.php?goto=https://ste-b2b.agency/
%u If you are going for best contents like me, simply pay a visit this web site all the time for the reason that it gives feature contents, thankshttp://L.v.Eli.Ne.S.Swxzu%40Hu.Feng.Ku.Angn..Ub..xn--.Xn--.U.K37@cgi.members.interq.or.jp/ox/shogo/ONEE/g_book/g_book.cgi
%u hi!,I like your writing so a lot! share we keep in touch extra approximately your post on AOL? I require an expert on this house to unravel my problem. May be that's you! Looking forward to peer you. http://aquarium-vl.ru/forum/go.php?url=aHR0cDovL20ud3d3LnBvbGFya29yZWEuY28ua3IvbWVtYmVyL2xvZ2luLmh0bWw/bm9NZW1iZXJPcmRlcj0mcmV0dXJuVXJsPWh0dHAlM2ElMmYlMmZzdGUtYjJiLmFnZW5jeS8
%u This article will help the internet visitors for setting up new web site or even a blog from start to end.http://np26.ru/bitrix/redirect.php?goto=https://ste-b2b.agency
%u Hi just wanted to give you a quick heads up and let you know a few of the images aren't loading properly. I'm not sure why but I think its a linking issue. I've tried it in two different browsers and both show the same results.http://3h.kz/go.php?url=https://www.google.de/url?q=https://ste-b2b.agency/
%u Right here is the perfect blog for anyone who wishes to find out about this topic. You understand a whole lot its almost hard to argue with you (not that I actually would want to…HaHa). You certainly put a new spin on a topic that has been written about for ages. Excellent stuff, just wonderful!https://meelameelo.ru/bitrix/redirect.php?goto=https://ste-b2b.agency/
%u This information is worth everyone's attention. When can I find out more?http://www.eticostat.it/stat/dlcount.php?id=cate11&url=https://lamortazza.ru/bitrix/redirect.php?goto=https://ste-b2b.agency/
%u Whats up this is somewhat of off topic but I was wondering if blogs use WYSIWYG editors or if you have to manually code with HTML. I'm starting a blog soon but have no coding experience so I wanted to get advice from someone with experience. Any help would be enormously appreciated!https://www.wbc.poznan.pl/dlibra/login?refUrl=aHR0cDovL20uc2hvcGlubmV3eW9yay5uZXQvcmVkaXJlY3QuYXNweD91cmw9c3RlLWIyYi5hZ2VuY3k&utm_source=dms_trafficaffiliates&utm_medium=dms_cashkaro_rev&utm_campaign=dms_trafficaffiliates_cashkaro_rev_ENKR20230921A612473516_4_42_68ead8c002e59700019b47aa
http://m.shopinstlouis.com/redirect.aspx?url=https://my-pet-extra.store/ Hey there! I could have sworn I've been to this blog before but after reading through some of the post I realized it's new to me. Nonetheless, I'm definitely delighted I found it and I'll be bookmarking and checking back frequently!http://m.shopinstlouis.com/redirect.aspx?url=https://my-pet-extra.store/
https://my-pet-extra.store/ A fascinating discussion is definitely worth comment. I do believe that you need to publish more about this subject matter, it may not be a taboo subject but usually people don't discuss such subjects. To the next! Kind regards!!https://my-pet-extra.store/
http://stmann.ru/bitrix/redirect.php?goto=https://my-pet-extra.store/ Hey There. I discovered your weblog the use of msn. That is a very smartly written article. I'll make sure to bookmark it and come back to read more of your helpful info. Thanks for the post. I'll definitely return.http://stmann.ru/bitrix/redirect.php?goto=https://my-pet-extra.store/