Vulnerabilities > CVE-2006-0625 - Unspecified vulnerability in Spip 1.8.2D/1.8.2E/1.8.2G

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
spip
exploit available

Summary

Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include arbitrary files via ".." sequences in the GLOBALS[type_urls] parameter, which could then be used to execute arbitrary code via resultant direct static code injection in the file parameter to spip_acces_doc.php3.

Vulnerable Configurations

Part Description Count
Application
Spip
3

Exploit-Db

descriptionSPIP 1.8.2 Spip_RSS.PHP Remote Command Execution Vulnerability. CVE-2006-0625. Webapps exploit for php platform
idEDB-ID:27172
last seen2016-02-03
modified2006-02-08
published2006-02-08
reporterrgod
sourcehttps://www.exploit-db.com/download/27172/
titleSPIP 1.8.2 Spip_RSS.PHP Remote Command Execution Vulnerability