SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/36008 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/52381 | vdb entry |
http://secunia.com/advisories/36365 | third party advisory vendor advisory |
http://www.spip-contrib.net/SPIP-Security-Alert-new-version | patch vendor advisory |
http://fil.rezo.net/secu-14346-14350+14354.patch | patch |