RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spip | Spip | 3.1.13 (including) | 4.1.2 (including) |
Spip | Ubuntu | bionic | * |
Spip | Ubuntu | kinetic | * |
Spip | Ubuntu | lunar | * |
Spip | Ubuntu | mantic | * |
Spip | Ubuntu | trusty | * |
Spip | Ubuntu | xenial | * |