← back
CVE-2013-4557

CVE-2013-4557

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 25%
from disclosure to weapon0 days
Published on NVDNov 15
metasploitJul 4
exploitation probability
25%top 2% of all CVEs
observed exploitation
nono source reports it
The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execute arbitrary PHP via the connect parameter.
Affected products
n/a · n/a