CVE-2016-3153: Code Injection
Published Apr 8, 2016
·Updated
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrerentites function.
Affected Software
63 affected components
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Spip SPIP=2.0.0
Spip SPIP=2.0.1
Spip SPIP=2.0.2
Spip SPIP=2.0.3
Spip SPIP=2.0.4
Spip SPIP=2.0.5
Spip SPIP=2.0.6
Spip SPIP=2.0.7
Spip SPIP=2.0.8
Spip SPIP=2.0.9
Spip SPIP=2.0.10
Spip SPIP=2.0.11
Spip SPIP=2.0.12
Spip SPIP=2.0.13
Spip SPIP=2.0.14
Spip SPIP=2.0.15
Spip SPIP=2.0.16
Spip SPIP=2.0.17
Spip SPIP=2.0.18
Spip SPIP=2.0.19
Spip SPIP=2.0.20
Spip SPIP=2.0.21
Spip SPIP=2.0.22
Spip SPIP=2.1.1
Spip SPIP=2.1.2
Spip SPIP=2.1.3
Spip SPIP=2.1.4
Spip SPIP=2.1.5
Spip SPIP=2.1.6
Spip SPIP=2.1.7
Spip SPIP=2.1.8
Spip SPIP=2.1.9
Spip SPIP=2.1.10
Spip SPIP=2.1.11
Spip SPIP=2.1.12
Spip SPIP=2.1.13
Spip SPIP=2.1.14
Spip SPIP=2.1.15
Spip SPIP=2.1.16
Spip SPIP=2.1.17
Spip SPIP=2.1.18
Spip SPIP=3.0.0
Spip SPIP=3.0.1
Spip SPIP=3.0.2
Spip SPIP=3.0.3
Spip SPIP=3.0.4
Spip SPIP=3.0.5
Spip SPIP=3.0.6
Spip SPIP=3.0.7
Spip SPIP=3.0.8
Spip SPIP=3.0.9
Spip SPIP=3.0.10
Spip SPIP=3.0.11
Spip SPIP=3.0.13
Spip SPIP=3.0.14
Spip SPIP=3.0.15
Spip SPIP=3.0.16
Spip SPIP=3.0.17
Spip SPIP=3.0.19
Spip SPIP=3.0.20
Spip SPIP=3.1.0
Remediation
Event History
Apr 8, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3153?
CVE-2016-3153 is classified as a critical vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2016-3153?
To remediate CVE-2016-3153, upgrade your SPIP installation to version 3.1.1 or later, or 3.0.22 or later.
3
What versions are affected by CVE-2016-3153?
CVE-2016-3153 affects SPIP versions 2.x before 2.1.19, and versions 3.0.x before 3.0.22, as well as 3.1.x before 3.1.1.
4
Can CVE-2016-3153 be exploited remotely?
Yes, CVE-2016-3153 allows remote attackers to execute arbitrary PHP code, making it exploitable over the internet.
5
What impact does CVE-2016-3153 have on SPIP?
The impact of CVE-2016-3153 is severe as it can lead to full server compromise through arbitrary code execution.