Web Hack List

Preliminary research

Casse-Spip - From an Unauthenticated SQL Injection to Remote Command Execution

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

SPIP vulnerabilities combine an unauthenticated SQL injection, missing action authorization and mass assignment. The article explains how these flaws enable administrator account takeover or command execution through the job queue, and records the fixes in SPIP 4.4.18.

Record

Researcher
Franck Chevalier

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Franck Chevalier, first published at the original source. Preserved copies are kept so the citation survives its host.