CVE-2016-7981
MEDIUM NUCLEISpip < 3.1.2 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.
Nuclei Templates (1)
SPIP <3.1.2 - Cross-Site Scripting
MEDIUMby pikpikcu
Shodan:
http.html:"spip.php?page=backend" || cpe:"cpe:2.3:a:spip:spip"
FOFA:
body="spip.php?page=backend"
References (7)
Scores
CVSS v3
6.1
EPSS
0.3700
EPSS Percentile
97.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Classification
CWE
CWE-79
Status
published
Affected Products (2)
spip/spip
< 3.1.2
n/a/n/a
Timeline
Published
Jan 18, 2017
Tracked Since
Feb 18, 2026