It has been reported that SPIP may be prone to an unspecifed PHP code execution vulnerability that could allow an attacker to inject arbitrary PHP code via certain URI parameters of 'forum.php3' script. Successful exploitation of this issue may allow an attacker to execute malicous PHP code in the context of the vulnerable site. Although unconfirmed, SPIP versions 1.7 and prior may be prone to these issues.
It has been reported that SPIP may be prone to an unspecifed PHP code execution vulnerability that could allow an attacker to inject arbitrary PHP code via certain URI parameters of 'forum.php3' script. Successful exploitation of this issue may allow an attacker to execute malicous PHP code in the context of the vulnerable site. Although unconfirmed, SPIP versions 1.7 and prior may be prone to these issues.