Untriaged
SPIP < 4.4.10 SQL Injection RCE via Union & PHP Tags
SPIP versions prior to 4.4.10 contain a SQL injection vulnerability that allows authenticated low-privilege users to execute arbitrary SQL queries by manipulating union-based injection techniques. Attackers can exploit this SQL injection flaw combined with PHP tag processing to achieve remote code execution on the server.
References
-
-
https://git.spip.net/spip/spip product
-
https://www.vulncheck.com/advisories/spip-sql-injection-rce-via-union-php-tags third-party-advisory
Affected products
SPIP
- <4.4.10
Matching in nixpkgs
pkgs.spip
A random forest model for splice prediction in genomics
-
nixos-unstable 0-unstable-2023-04-19
- nixpkgs-unstable 0-unstable-2023-04-19
- nixos-unstable-small 0-unstable-2023-04-19
-
nixos-25.11 0-unstable-2023-04-19
- nixos-25.11-small 0-unstable-2023-04-19
- nixpkgs-25.11-darwin 0-unstable-2023-04-19
pkgs.spiped
Utility for secure encrypted channels between sockets
pkgs.aespipe
AES encrypting or decrypting pipe
Package maintainers
-
@martijnvermaat Martijn Vermaat <martijn@vermaat.name>
-
@apraga Alexis Praga <alexis.praga@proton.me>
-
@thoughtpolice Austin Seipp <aseipp@pobox.com>