CVE-2016-3154
published 2016-04-08CVE-2016-3154: The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to…
PriorityP355critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.84%
76.5th percentile
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | nifi | — | — |
| debian | spip | < spip 3.0.22-1 (bullseye) | spip 3.0.22-1 (bullseye) |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
| spip | spip | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_apache5.4
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5fwq-26jx-xp73: The encoder_contexte_ajax function in ecrire/inc/filtres
ghsa_unreviewed·2022-05-17
CVE-2016-3154 [CRITICAL] CWE-94 GHSA-5fwq-26jx-xp73: The encoder_contexte_ajax function in ecrire/inc/filtres
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
OSV
CVE-2016-3154: The encoder_contexte_ajax function in ecrire/inc/filtres
osv·2016-04-08·CVSS 9.8
CVE-2016-3154 [CRITICAL] CVE-2016-3154: The encoder_contexte_ajax function in ecrire/inc/filtres
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
Debian
CVE-2016-3154: spip - The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before ...
vendor_debian·2016·CVSS 9.8
CVE-2016-3154 [CRITICAL] CVE-2016-3154: spip - The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before ...
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.
Scope: local
bullseye: resolved (fixed in 3.0.22-1)
forky: resolved (fixed in 3.0.22-1)
sid: resolved (fixed in 3.0.22-1)
trixie: resolved (fixed in 3.0.22-1)
Apache
Apache nifi: CVE-2016-8748
vendor_apache·CVSS 5.4
CVE-2016-8748 Apache nifi: CVE-2016-8748
Apache nifi: CVE-2016-8748
Title: Potential Cross-Site Scripting in Connection Details Dialog Published: 2016-12-19 Severity: Medium Products: Apache NiFi Affected Versions: 1.0.0 and 1.1.0 Fixed Versions: 1.0.1 and 1.1.1 Reporter: Matt Gilman References CVE Record: CVE-2016-8748 NVD Record: CVE-2016-8748 Apache Jira Issue: NIFI-3154 GitHub Pull Request: 1305 There is a cross-site scripting vulnerability in connection details dialog when accessed by an authorized user. The user supplied text was not being properly handled when added to the DOM. The vulnerability was resolved after reviewing the pull request when merging changes. Users running a prior release should upgrade to 1.0.1 or 1.1.1.
Severity: moderate
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.debian.org/security/2016/dsa-3518https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-1-1-SPIP-3-0-22-et-SPIP-2-1.html?lang=frhttps://core.spip.net/projects/spip/repository/revisions/22903http://www.debian.org/security/2016/dsa-3518https://blog.spip.net/Mise-a-jour-CRITIQUE-de-securite-Sortie-de-SPIP-3-1-1-SPIP-3-0-22-et-SPIP-2-1.html?lang=frhttps://core.spip.net/projects/spip/repository/revisions/22903
2016-04-08
Published