CVE-2006-0625 is a directory traversal vulnerability in Spip_RSS.PHP within SPIP versions 1.8.2g and earlier. This flaw allows remote attackers to read or include arbitrary files by manipulating the GLOBALS[type_urls] parameter with ".." sequences. Successful exploitation could lead to arbitrary code execution through static code injection in spip_acces_doc.php3. The vulnerability has a CVSS score of 6.4, indicating a medium severity. It is easily exploitable over the network with low attack complexity and no authentication required, potentially leading to partial confidentiality and integrity impacts. While there is no evidence of active exploitation in the wild or Metasploit/Nuclei modules, an ExploitDB entry (EDB-27172) confirms the existence of remote command execution exploit code. Despite this, the CVE has garnered minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.8.2dCPE matchmatch criteria | cpe:2.3:a:spip:spip:1.8.2d:*:*:*:*:*:*:* | ||
1.8.2eCPE matchmatch criteria | cpe:2.3:a:spip:spip:1.8.2e:*:*:*:*:*:*:* | ||
1.8.2gCPE matchmatch criteria | cpe:2.3:a:spip:spip:1.8.2g:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.