CVE-2017-9736: OS Command Injection
Published Jun 17, 2017
·Updated
SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution.
Affected Software
14 affected components
Spip SPIP=3.1.0
Spip SPIP=3.1.0-alpha
Spip SPIP=3.1.0-beta
Spip SPIP=3.1.0-rc
Spip SPIP=3.1.0-rc2
Spip SPIP=3.1.0-rc3
Spip SPIP=3.1.1
Spip SPIP=3.1.2
Spip SPIP=3.1.3
Spip SPIP=3.1.4
Spip SPIP=3.1.5
Spip SPIP=3.2-alpha-1
Spip SPIP=3.2.0-beta
Spip SPIP=3.2.0-beta2
Remediation
Event History
Jun 17, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9736?
CVE-2017-9736 has been classified as a critical vulnerability as it allows remote code execution.
2
How do I fix CVE-2017-9736?
To fix CVE-2017-9736, upgrade your SPIP installation to version 3.1.6 or 3.2 Beta 3 or later.
3
Which versions of SPIP are affected by CVE-2017-9736?
CVE-2017-9736 affects SPIP versions 3.1.x before 3.1.6 and 3.2.x before Beta 3.
4
What type of attack can be executed due to CVE-2017-9736?
CVE-2017-9736 allows remote attackers to execute arbitrary code on vulnerable SPIP installations.
5
Is there a patch available for CVE-2017-9736?
Yes, a patch is included in SPIP versions 3.1.6 and 3.2 Beta 3 to mitigate CVE-2017-9736.