296,202
Total vulnerabilities in the database
SPIP before 3.1.11 and 3.2 before 3.2.5 provides different error messages from the password-reminder page depending on whether an e-mail address exists, which might help attackers to enumerate subscribers.
Software | From | Fixed in |
---|---|---|
spip / spip | 3.2.0 | 3.2.5 |
spip / spip | - | 3.1.11 |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |
debian / debian_linux | 10.0 | 10.0.x |
canonical / ubuntu_linux | 18.04 | 18.04.x |