Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

21 – 30 of 46 results


CVE-2019-16393

Medium priority

Some fixes available 1 of 4

SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-16392

Medium priority

Some fixes available 1 of 4

SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-16391

Medium priority

Some fixes available 1 of 4

SPIP before 3.1.11 and 3.2 before 3.2.5 allows authenticated visitors to modify any published content and execute other modifications in the database. This is related to ecrire/inc/meta.php and ecrire/inc/securiser_action.php.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2019-11071

Medium priority

Some fixes available 1 of 3

SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Fixed Not affected
Show less packages

CVE-2017-15736

Medium priority

Some fixes available 1 of 4

Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web script or HTML via a crafted string, as demonstrated by a PGP field, related...

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Not affected Fixed Vulnerable
Show less packages

CVE-2017-9736

High priority
Ignored

SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected
Show less packages

CVE-2016-7999

Medium priority
Vulnerable

ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the var_url parameter in a valider_xml action.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-7998

Medium priority
Vulnerable

The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with...

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-7982

Medium priority
Vulnerable

Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2016-7981

Medium priority
Vulnerable

Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.

1 affected packages

spip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
spip Not affected Not affected Not affected Not affected Vulnerable
Show less packages