SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spip | Spip | 4.0.0 (including) | 4.1.18 (excluding) |
Spip | Spip | 4.2.0 (including) | 4.2.15 (including) |
Spip | Spip | 4.3.0 (including) | 4.3.0 (including) |
Spip | Spip | 4.3.1 (including) | 4.3.1 (including) |
Spip | Ubuntu | upstream | * |