Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-3041

Опубликовано: 01 сент. 2009
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:spip:spip:1.9:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:1.9:alpha2:*:*:*:*:*:*
cpe:2.3:a:spip:spip:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:1.9.2c:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:1.9.2d:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:1.9.2g:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:1.9.2h:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:1.9.alpha1:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:spip:spip:2.0.8:*:*:*:*:*:*:*

EPSS

Процентиль: 93%
0.06589
Низкий

7.5 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
почти 17 лет назад

SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.

debian
почти 17 лет назад

SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper acc ...

github
больше 4 лет назад

SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.

EPSS

Процентиль: 93%
0.06589
Низкий

7.5 High

CVSS2

Дефекты

CWE-264