Lucene search

K
cve[email protected]CVE-2009-3041
HistorySep 01, 2009 - 6:30 p.m.

CVE-2009-3041

2009-09-0118:30:04
CWE-264
web.nvd.nist.gov
27
cve-2009-3041
spip
security vulnerability
access control
unauthorized activities
installation
backups
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

Low

0.073 Low

EPSS

Percentile

94.1%

SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.

Affected configurations

NVD
Node
spipspipMatch1.9
OR
spipspipMatch1.9alpha2
OR
spipspipMatch1.9.1
OR
spipspipMatch1.9.2c
OR
spipspipMatch1.9.2d
OR
spipspipMatch1.9.2g
OR
spipspipMatch1.9.2h
OR
spipspipMatch1.9.alpha1
OR
spipspipMatch2.0rc1
OR
spipspipMatch2.0.0
OR
spipspipMatch2.0.1
OR
spipspipMatch2.0.2
OR
spipspipMatch2.0.3
OR
spipspipMatch2.0.4
OR
spipspipMatch2.0.5
OR
spipspipMatch2.0.6
OR
spipspipMatch2.0.7
OR
spipspipMatch2.0.8

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

Low

0.073 Low

EPSS

Percentile

94.1%