296,213
Total vulnerabilities in the database
SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.
Software | From | Fixed in |
---|---|---|
spip / spip | 1.9.1 | 1.9.1.x |
spip / spip | 1.9-alpha2 | 1.9-alpha2.x |
spip / spip | 2.0.0 | 2.0.0.x |
spip / spip | 2.0.3 | 2.0.3.x |
spip / spip | 2.0.6 | 2.0.6.x |
spip / spip | 1.9 | 1.9.x |
spip / spip | 2.0.7 | 2.0.7.x |
spip / spip | 2.0-rc1 | 2.0-rc1.x |
spip / spip | 2.0.8 | 2.0.8.x |
spip / spip | 2.0.2 | 2.0.2.x |
spip / spip | 2.0.5 | 2.0.5.x |
spip / spip | 1.9.2g | 1.9.2g.x |
spip / spip | 1.9.2h | 1.9.2h.x |
spip / spip | 2.0.1 | 2.0.1.x |
spip / spip | 1.9.2c | 1.9.2c.x |
spip / spip | 1.9.2d | 1.9.2d.x |
spip / spip | 2.0.4 | 2.0.4.x |
spip / spip | 1.9.alpha1 | 1.9.alpha1.x |