The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
PoC: CVE-2024-7954
Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12
PoC: CVE-2024-7954
This exploit will attempt to execute system commands on SPIP targets.
PoC: CVE-2024-7954
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request.
PoC: Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954-
Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)
PoC: RCE_CVE-2024-7954-
The porte_plume plugin used by SPIP before 4.30-alpha2, 4.2.13, and 4.1.16 is vulnerable to an arbitrary code execution vulnerability. A remote and unauthenticated attacker can execute arbitrary PHP as the SPIP user by sending a crafted HTTP request. (CRITICAL)
PoC: CVE-2024-7954POC
SPIP 4.30-alpha2、4.2.13、4.1.16之前的版本使用的porte_plume插件存在任意代码执行漏洞,远程未经身份验证的攻击者可以通过发送精心设计的HTTP 请求以SPIP用户身份执行任意PHP代码。
PoC: CVE-2024-7954-RCE
Unauthenticated Remote Code Execution in SPIP versions up to and including 4.2.12
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free