CVE-2019-11071
10.04.2019, 21:29
SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server because var_memotri is mishandled.Enginsight
Vendor | Product | Version |
---|---|---|
spip | spip | 3.1.0 ≤ 𝑥 < 3.1.10 |
spip | spip | 3.2.0 ≤ 𝑥 < 3.2.4 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References