.. / CVE-2016-7981

Exploit for SPIP <3.1.2 - Cross-Site Scripting (CVE-2016-7981)

Description:

SPIP 3.1.2 and earlier contains a cross-site scripting vulnerability in valider_xml.php which allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.

Nuclei Template

View the template here CVE-2016-7981.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2016/CVE-2016-7981.yaml
Copy

References:

https://core.spip.net/projects/spip/repository/revisions/23201
https://core.spip.net/projects/spip/repository/revisions/23202
https://core.spip.net/projects/spip/repository/revisions/23200
http://www.openwall.com/lists/oss-security/2016/10/05/17
https://nvd.nist.gov/vuln/detail/CVE-2016-7981