Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2016-7980
Description:Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted valider_xml request. NOTE: this issue can be combined with CVE-2016-7998 to execute arbitrary PHP code.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.2.2016.695  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2016-7980
BugTraq ID: 93451
http://www.securityfocus.com/bid/93451
https://sysdream.com/news/lab/2016-10-19-spip-3-1-2-exec-code-cross-site-request-forgery-cve-2016-7980/
http://www.openwall.com/lists/oss-security/2016/10/05/17
http://www.openwall.com/lists/oss-security/2016/10/06/6
http://www.openwall.com/lists/oss-security/2016/10/12/6




© 1998-2025 E-Soft Inc. All rights reserved.