CVE-2013-4557: Code Injection
Published Nov 15, 2013
·Updated
The Security Screen (core/securite/ecransecurite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execute arbitrary PHP via the connect parameter.
Affected Software
13 affected componentsFixes available
debian/spip
3.2.4-1+deb10u93.2.4-1+deb10u113.2.11-3+deb11u93.2.11-3+deb11u74.1.9+dfsg-1+deb12u24.1.12+dfsg-1
Spip SPIP=3.0.0
Spip SPIP=3.0.1
Spip SPIP=3.0.2
Spip SPIP=3.0.3
Spip SPIP=3.0.4
Spip SPIP=3.0.5
Spip SPIP=3.0.6
Spip SPIP=3.0.7
Spip SPIP=3.0.8
Spip SPIP=3.0.9
Spip SPIP=3.0.10
Spip SPIP=3.0.11
Remediation
Event History
Nov 15, 2013
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4557?
CVE-2013-4557 has a high severity due to its ability to allow remote attackers to execute arbitrary PHP code.
2
How do I fix CVE-2013-4557?
To fix CVE-2013-4557, upgrade to SPIP version 3.0.12 or later, or apply the appropriate security patches.
3
Which versions of SPIP are affected by CVE-2013-4557?
CVE-2013-4557 affects SPIP versions prior to 3.0.12, including 3.0.0 to 3.0.11.
4
What is the exploit mechanism for CVE-2013-4557?
The exploit mechanism for CVE-2013-4557 involves manipulating the 'connect' parameter in Security Screen.
5
Can CVE-2013-4557 lead to full server compromise?
Yes, CVE-2013-4557 can potentially lead to full server compromise due to remote code execution vulnerabilities.