[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2016-3154 -- spip

ID: oval:org.secpod.oval:def:1901108Date: (C)2019-03-04   (M)2023-12-20
Class: VULNERABILITYFamily: unix




The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
spip
Reference:
CVE-2016-3154
CVE    1
CVE-2016-3154
CPE    58
cpe:/a:spip:spip:2.1.9
cpe:/a:spip:spip:2.1.7
cpe:/a:spip:spip:2.1.8
cpe:/a:spip:spip:2.1.1
...

© SecPod Technologies