Vulnerabilities
Vulnerable Software
Spip:  >> Spip  >> 3.1.3  Security Vulnerabilities
SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/info_plugin.php involving the `$plugin` parameter, as demonstrated by a /ecrire/?exec=info_plugin URL.
CVSS Score
6.1
EPSS Score
0.009
Published
2016-12-17
Cross-site scripting (XSS) vulnerability in ecrire/exec/plonger.php in SPIP 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the rac parameter.
CVSS Score
6.1
EPSS Score
0.011
Published
2016-12-05


Contact Us

Shodan ® - All rights reserved