Web Hack List

Preliminary research

Casse-Spip - From an Unauthenticated SQL Injection to Remote Command Execution

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

SPIP vulnerabilities combine an unauthenticated SQL injection, missing action authorization and mass assignment. The article explains how these flaws enable administrator account takeover or command execution through the job queue, and records the fixes in SPIP 4.4.18.

Record

Researcher
Franck Chevalier
Published by
blog.lexfo.fr
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Franck Chevalier, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .