Debian Spip vulnerabilities
68 known vulnerabilities affecting debian/spip.
Total CVEs
68
CISA KEV
0
Public exploits
14
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH19MEDIUM36LOW4
Vulnerabilities
Page 4 of 4
CVE-2006-1702HIGHCVSS 7.5PoCfixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-1702 [HIGH] CVE-2006-1702: spip - PHP remote file inclusion vulnerability in spip_login.php3 in SPIP 1.8.3 allows ...
PHP remote file inclusion vulnerability in spip_login.php3 in SPIP 1.8.3 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.
Scope: local
bullseye: resolved (fixed in 2.0.6-1)
forky: resolved (fixed in 2.0.6-1)
sid: resolved (fixed in 2.0.6-1)
trixie: resolved (fixed in 2.0.6-1)
debian
CVE-2006-0625MEDIUMCVSS 6.4PoCfixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-0625 [MEDIUM] CVE-2006-0625: spip - Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier all...
Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via ".." sequences in the GLOBALS[type_urls] parameter, which could then be used to execute arbitrary code via resultant direct static code injection in the file parameter to spip_acces_doc.php3.
Scope: local
bullseye: resolved (fixed
debian
CVE-2006-0518MEDIUMCVSS 4.3PoCfixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-0518 [MEDIUM] CVE-2006-0518: spip - Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earli...
Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Scope: local
bullseye: resolved (fixed in 2.0.6-1)
forky: resolved (fixed in 2.0.6-1)
sid: resolved (fixed in 2.0.6-1)
trixie: resolved (fixed in 2.0.6-1)
debian
CVE-2006-1295MEDIUMCVSS 4.3fixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-1295 [MEDIUM] CVE-2006-1295: spip - Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allow...
Cross-site scripting (XSS) vulnerability in recherche.php3 in SPIP 1.8.2-g allows remote attackers to inject arbitrary web script or HTML via the recherche parameter.
Scope: local
bullseye: resolved (fixed in 2.0.6-1)
forky: resolved (fixed in 2.0.6-1)
sid: resolved (fixed in 2.0.6-1)
trixie: resolved (fixed in 2.0.6-1)
debian
CVE-2006-0626MEDIUMCVSS 7.5PoCfixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-0626 [HIGH] CVE-2006-0626: spip - SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier al...
SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitrary SQL commands via the file parameter.
Scope: local
bullseye: resolved (fixed in 2.0.6-1)
forky: resolved (fixed in 2.0.6-1)
sid: resolved (fixed in 2.0.6-1)
trixie: resolved (fixed in 2.0.6-1)
debian
CVE-2006-0517MEDIUMCVSS 7.5fixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-0517 [HIGH] CVE-2006-0517: spip - Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 ...
Multiple SQL injection vulnerabilities in formulaires/inc-formulaire_forum.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id_forum, (2) id_article, or (3) id_breve parameters to forum.php3; (4) unspecified vectors related to "session handling"; and (5) when posting "petitions".
Scop
debian
CVE-2006-0519MEDIUMCVSS 5.0fixed in spip 2.0.6-1 (bullseye)2006
CVE-2006-0519 [MEDIUM] CVE-2006-0519: spip - SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attack...
SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier allows remote attackers to obtain sensitive information via a direct request to inc-messforum.php3, which reveals the path in an error message.
Scope: local
bullseye: resolved (fixed in 2.0.6-1)
forky: resolved (fixed in 2.0.6-1)
sid: resolved (fixed in 2.0.6-1)
trixie: resolved (fixed in 2.0.6-1)
debian
CVE-2005-4494MEDIUMCVSS 2.6fixed in spip 2.0.6-1 (bullseye)2005
CVE-2005-4494 [LOW] CVE-2005-4494: spip - Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier allows remote...
Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) spip_login.php3 and (2) spip_pass.php3.
Scope: local
bullseye: resolved (fixed in 2.0.6-1)
forky: resolved (fixed in 2.0.6-1)
sid: resolved (fixed in 2.0.6-1)
trixie: resolved (fixed in 2.0.6-1)
debian
← Previous4 / 4