⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.
CVE-2009-3041 — Spip vulnerability
Severity
7.5HIGHNVD
EPSS
3.8%
top 11.80%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedSep 1
Latest updateMay 2
Description
SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.
CVSS vector
AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4
Affected Packages3 packages
Patches
🔴Vulnerability Details
3💥Exploits & PoCs
1📋Vendor Advisories
1Debian▶
CVE-2009-3041: spip - SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access contro...↗2009