HIGH
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php
Published Jul 9, 2013
7.5
HIGHCVSS 2.0
EPSS 8.98%
Description
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.
Affected products
No data.
Configuration 1
Configuration 2
OR
- 2.1.1
- 2.1.2
- 2.1.3
- 2.1.4
- 2.1.5
- 2.1.6
- 2.1.7
- 2.1.8
- 2.1.9
- 2.1.10
- 2.1.11
- 2.1.12
- 2.1.13
- 2.1.14
- 2.1.15
- 2.1.16
- 2.1.17
- 2.1.18
- 2.1.19
- 2.1.20
- 2.1.21
Configuration 3
OR
- 2.0.0
- 2.0.1
- 2.0.2
- 2.0.3
- 2.0.4
- 2.0.5
- 2.0.6
- 2.0.7
- 2.0.8
- 2.0.9
- 2.0.10
- 2.0.11
- 2.0.12
- 2.0.13
- 2.0.14
- 2.0.15
- 2.0.16
- 2.0.17
- 2.0.18
- 2.0.19
- 2.0.20
- 2.0.21
- 2.0.22
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (4)
- http://contrib.spip.net/SPIP-3-0-9-2-1-22-2-0-23-corrections-de-bug-et-faille?lang=fr x_refsource_CONFIRMVendor Advisory
- http://core.spip.org/projects/spip/repository/revisions/20541 x_refsource_MISC
- http://www.debian.org/security/2013/dsa-2694 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2013/05/27/2 mailing-listx_refsource_MLIST
| Link | Providers | Tags |
|---|---|---|
| http://contrib.spip.net/SPIP-3-0-9-2-1-22-2-0-23-corrections-de-bug-et-faille?lang=fr | x_refsource_CONFIRMVendor Advisory | |
| http://core.spip.org/projects/spip/repository/revisions/20541 | x_refsource_MISC | |
| http://www.debian.org/security/2013/dsa-2694 | vendor-advisoryx_refsource_DEBIAN | |
| http://www.openwall.com/lists/oss-security/2013/05/27/2 | mailing-listx_refsource_MLIST |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 9, 2013
Updated Sep 16, 2024
Reserved Feb 19, 2013
Link CVE-2013-2118
CISA Vulnrichment
Updated n/a