Spid is a narrowly scoped identity and access management platform with a compact product portfolio centered on its core Spid offering, which handles authentication and authorization services. The observed vulnerability profile clusters around path-traversal weaknesses that allow directory-access violations, reflecting common risks in file-path handling and access-control logic within identity systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spid over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0976MEDIUM Directory traversal vulnerability in scan_lang_insert.php in Boris Herbiniere-Seve SPiD 1.3.1 allows remote attackers to read arbitrary files via the lang parameter. | Mar 3, 2006 | 5.0 | 23 | NO | YES |
CVE-2005-2198HIGH PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter. | Jul 11, 2005 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spid.
Media articles that mention a CVE ID that affects a product developed by Spid — matched by CVE ID, not by vendor name.