Unrated severityNVD Advisory· Published Sep 1, 2009· Updated Apr 23, 2026
CVE-2009-3041
CVE-2009-3041
Description
SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.
Affected products
18cpe:2.3:a:spip:spip:1.9:*:*:*:*:*:*:*+ 17 more
- cpe:2.3:a:spip:spip:1.9:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:1.9.1:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:1.9.2c:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:1.9.2d:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:1.9.2g:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:1.9.2h:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:1.9.alpha1:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:1.9:alpha2:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:2.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:2.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:2.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:2.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:2.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:2.0:rc1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- fil.rezo.net/secu-14346-14350+14354.patchnvdPatch
- www.spip-contrib.net/SPIP-Security-Alert-new-versionnvdPatchVendor Advisory
- www.securityfocus.com/bid/36008nvdExploit
- secunia.com/advisories/36365nvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/52381nvd
News mentions
0No linked articles in our index yet.