目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2024-7954— SPIP 安全漏洞

一分钟漏洞结论

影响对象
SPIP SPIP
利用判断
存在公开或 AI PoC,应优先验证
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

SPIP是SPIP开源的一个用于创建 Internet 站点的免费软件。 SPIP存在安全漏洞,该漏洞源于容易受到任意代码执行漏洞的影响,远程未经身份验证的攻击者可以通过发送精心设计的HTTP请求以SPIP用户身份执行任意PHP。

CVSS 9.8 · Critical EPSS 90.05% · P100
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2024-7954 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
SPIP porte_plume Plugin Arbitrary PHP Execution
来源: CVE Program / CVE List V5
Vulnerability Description
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
动态执行代码中指令转义处理不恰当(Eval注入)
来源: CVE Program / CVE List V5
Vulnerability Title
SPIP 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
SPIP是SPIP开源的一个用于创建 Internet 站点的免费软件。 SPIP存在安全漏洞,该漏洞源于容易受到任意代码执行漏洞的影响,远程未经身份验证的攻击者可以通过发送精心设计的HTTP请求以SPIP用户身份执行任意PHP。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

神龙十问 — AI 深度分析

十问解析:根本原因、利用方式、修复建议、紧迫性。摘要免费,完整版需登录。

受影响产品

厂商 产品 影响版本 CPE 订阅
SPIP SPIP 4.3.0-alpha ~ 4.3.0-alpha2 -

二、漏洞 CVE-2024-7954 的公开POC

# POC 描述 源链接 神龙链接
1 Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12 https://github.com/Chocapikk/CVE-2024-7954 POC详情
2 This exploit will attempt to execute system commands on SPIP targets. https://github.com/bigb0x/CVE-2024-7954 POC详情
3 Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12 https://github.com/fa-rrel/CVE-2024-7954-RCE POC详情
4 None https://github.com/TheCyberguy-17/RCE_CVE-2024-7954 POC详情
5 None https://github.com/MuhammadWaseem29/RCE-CVE-2024-7954 POC详情
6 The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. https://github.com/issamiso/CVE-2024-7954 POC详情
7 Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12 https://github.com/gh-ost00/CVE-2024-7954-RCE POC详情
8 The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. https://github.com/issamjr/CVE-2024-7954 POC详情
9 SPIP 4.30-alpha2、4.2.13、4.1.16之前的版本使用的porte_plume插件存在任意代码执行漏洞,远程未经身份验证的攻击者可以通过发送精心设计的HTTP 请求以SPIP用户身份执行任意PHP代码。 https://github.com/zxj-hub/CVE-2024-7954POC POC详情
10 The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. (CRITICAL) https://github.com/0dayan0n/RCE_CVE-2024-7954- POC详情
11 None https://github.com/Arthikw3b/RCE-CVE-2024-7954 POC详情
12 The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-7954.yaml POC详情
13 None https://github.com/r0otk3r/CVE-2024-7954 POC详情
14 None https://github.com/nak000/RCE-CVE-2024-7954 POC详情
15 Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954) https://github.com/ShivanshKuntal/Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954- POC详情
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2024-7954 的情报信息

请登录查看更多情报信息。

CVE-2024-7954 厂商安全公告 (1)

CVE-2024-7954 安全博客文章 (1)

CVE-2024-7954 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2024-7954

匿名用户
2025-09-12 23:38:30

HorsePower Brands Omaha 2525 N 117tһ Avee #300, Omaha, NE 68164, United Stаtes 14029253112 Bookmarks

匿名用户
2026-03-08 04:39:15

https://globalwindday.org/wp-content/uploads/event-manager-uploads/event_banner/Emirates-Airlines-Book-Next-Flight-Out-by-Phone-Guide.pdf I do not even know how I ended up here, but I thought this post was great. I don't know who you are but certainly you are going to a famous blogger if you are not already ;) Cheers! https://globalwindday.org/wp-content/uploads/event-manager-uploads/event_banner/Emirates-Airlines-Book-Next-Flight-Out-by-Phone-Guide.pdf

匿名用户
2026-03-10 06:12:40

https://www.unsolvedcasefiles.com I am regular reader, how are you everybody? This post posted at this site is truly good.

匿名用户
2026-03-10 19:47:41

https://waiver.smartwaiver.com/e/GNbgYTWgaoZ2DV7TwYTqM7/web/ Yes! Finally someone writes about como. https://waiver.smartwaiver.com/e/GNbgYTWgaoZ2DV7TwYTqM7/web/

匿名用户
2026-03-11 12:08:49

Prime Secured 3603 N 222nd St, Suite 102, Elkhorn, NE 68022, United Stateѕ 402-289-4126 Pro Threat Secure

匿名用户
2026-03-11 14:17:47

Modern Purair 416 Meridian Ꭱd SΕ #14Α, Calgary AB T2Α 1X2, Canada (403) 800-7254 respiratory health

匿名用户
2026-03-12 07:24:13

Franchising Path Carlsbad Carlsbad, ᏟΑ 92008, United Stаtes +18587536197 how tօ start a jamba juice Franchise

匿名用户
2026-03-14 21:55:52

Boston Medical Group 3152Red Hill Ave. Ste. #280, Costa Mesa, ϹΑ 92626, United Stаtеѕ 800 337 7555 Bookmarks

匿名用户
2026-03-14 23:50:41

Concert Attire Stamford 360 Fairfield Ave, Stamford, CT 06902, United Տtates +12033298603 Fundraising chair

匿名用户
2026-03-15 01:58:57

Cabinet IQ 8305 Ѕtate Hwy 71 #110, Austin, TX 78735, United Ꮪtates 254-275-5536 Cabinetexperts

匿名用户
2026-03-17 07:55:50

recarga free fire,centro de recarga free fire,diamantes free fire,recargas free fire,recargar diamantes free fire,recargar diamantes free fire por id,recarga de free fire,recarga diamantes free fire,como recargar diamantes en free fire,garena free fire recarga,comprar diamantes para free fire,recargar free fire,free fire recarga,free fire recargasChoosing a protected, fast, and economical Wuthering Waves buy Lunite solution enables you to concentrate on what absolutely matters-- taking pleasure in the game.

匿名用户
2026-03-17 10:39:36

wuthering waves buy lunite,wuthering waves top up,free fire diamonds top up,free fire top upPicking a safe and secure, quick, and inexpensive Wuthering Waves buy Lunite solution allows you to focus on what genuinely matters-- enjoying the game.

匿名用户
2026-03-18 16:51:42

pubg mobile uc top up,pubg uc top upSelecting a secure, quickly, and budget friendly Wuthering Waves buy Lunite solution enables you to focus on what genuinely matters-- taking pleasure in the game.

匿名用户
2026-03-20 07:06:45

i m best seo expert https://www.imipe.org.mx/sites/default/files/webform/buzonoic/how-do-i-change-my-flight-on-the-chase-travel-portal-complete-guide-for-2026.pdf Mr. Tikki Bajaj

匿名用户
2026-08-08 19:31:08

https://prattmed.com/ Thank you a bunch for sharing this with all of us you actually understand what you're speaking approximately! Bookmarked. Please also visit my web site =). We could have a hyperlink change arrangement between us https://prattmed.com/

匿名用户
2026-08-08 19:31:37

https://misslaur.com/ Useful information. Fortunate me I found your web site accidentally, and I'm shocked why this twist of fate didn't took place earlier! I bookmarked it.https://misslaur.com/

匿名用户
2026-08-08 19:40:24

https://nutracompare.com/ Hello there, I found your web site by way of Google whilst searching for a similar topic, your web site came up, it seems great. I've bookmarked it in my google bookmarks. Hello there, just became alert to your blog via Google, and found that it's really informative. I am gonna be careful for brussels. I will be grateful should you proceed this in future. Lots of other people can be benefited from your writing. Cheers! https://nutracompare.com/

匿名用户
2026-08-08 23:33:09

https://supplementfan.com/ I'm very pleased to discover this page. I need to to thank you for ones time just for this wonderful read!! I definitely liked every little bit of it and i also have you bookmarked to look at new things in your web site. https://supplementfan.com/

匿名用户
2026-08-09 05:01:26

https://supplementresult.com/ Ridiculous quest there. What happened after? Thanks! https://supplementresult.com/


发表评论