Unrated severityNVD Advisory· Published Nov 18, 2013· Updated Apr 29, 2026
CVE-2013-4557
CVE-2013-4557
Description
The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execute arbitrary PHP via the connect parameter.
Affected products
12cpe:2.3:a:spip:spip:3.0.0:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:spip:spip:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:3.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:3.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:3.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:3.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:3.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:3.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:3.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:3.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:3.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:3.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:spip:spip:3.0.9:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- zone.spip.org/trac/spip-zone/changeset/75105/_core_/securite/ecran_securite.phpnvdExploitPatch
- secunia.com/advisories/55551nvdVendor Advisory
- www.openwall.com/lists/oss-security/2013/11/10/4nvd
- www.securitytracker.com/id/1029317nvd
- www.spip.net/fr_article5646.htmlnvd
- www.spip.net/fr_article5648.htmlnvd
- www.debian.org/security/2013/dsa-2794nvd
News mentions
0No linked articles in our index yet.