The porte_plume plugin for SPIP, prior to versions 4.30-alpha2, 4.2.13, and 4.1.16, contains an arbitrary code execution vulnerability. A remote, unauthenticated attacker can execute arbitrary PHP code as the SPIP user by sending a specially crafted HTTP request. The vulnerability is due to insufficient input validation in the plugin, allowing direct injection and execution of PHP code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
This repository contains a functional exploit for CVE-2024-7954, a critical unauthenticated remote code execution vulnerability in SPIP CMS version 4.2.8. The exploit is implemented in a single Python script ('cve_2024_7954_rce.py') and is accompanied by a detailed README. The script allows an attacker to execute arbitrary system commands on a vulnerable SPIP server by sending a specially crafted POST request to the '/index.php?action=porte_plume_previsu' endpoint, injecting PHP code via image tag preview rendering. The script extracts and displays the output of the executed command, and also fetches geolocation information about the target IP using the ipinfo.io API. Proxy support is included for traffic routing through tools like Burp Suite. The exploit is operational and can be used for real-world exploitation of unpatched SPIP 4.2.8 instances.
This repository contains a single Metasploit module (modules/exploits/multi/http/spip_porte_plume_previsu_rce.rb) that exploits CVE-2024-7954, a critical unauthenticated remote code execution vulnerability in SPIP (<= 4.2.12) with the porte_plume plugin (< 3.1.6). The exploit leverages a flaw in SPIP's templating system, specifically the mishandling of user-supplied input in the echappe_retour() and traitements_previsu_php_modeles_eval() functions, which leads to an eval() of attacker-controlled data. The module sends a crafted POST request to the /spip.php?action=porte_plume_previsu endpoint, injecting a base64-encoded PHP payload that is executed on the server. The exploit supports multiple payloads, including PHP Meterpreter and command shells for Unix/Linux and Windows platforms. The module includes version checks for both SPIP and the porte_plume plugin to determine exploitability. The code is weaponized, allowing for easy payload customization and reliable exploitation through the Metasploit framework.
This repository contains a Nuclei template (CVE-2024-7954.yaml) and a README.md describing an exploit for CVE-2024-7954, a critical remote code execution vulnerability in the SPIP CMS's porte_plume plugin (versions before 4.30-alpha2, 4.2.13, and 4.1.16). The exploit works by sending a crafted POST request to the /index.php?action=porte_plume_previsu endpoint with a payload that injects PHP code, allowing arbitrary command execution as the web server user. The Nuclei template automates this process and checks for successful exploitation by matching the presence of 'root:.*:0:0:' in the response body (indicating /etc/passwd was read) and the 'Composed-By: SPIP' header. The repository is structured for use with the Nuclei vulnerability scanner and is a proof-of-concept exploit, not a weaponized tool. No hardcoded IPs or domains are present; the main fingerprintable endpoint is the vulnerable HTTP POST path.
This repository provides a weaponized exploit for a Remote Code Execution (RCE) vulnerability in SPIP (up to version 4.2.12), affecting both Linux and Windows platforms. The vulnerability is due to improper handling of user-supplied input in SPIP's templating system, specifically in the porte_plume plugin, allowing arbitrary PHP code execution via a crafted POST request to /spip.php?action=porte_plume_previsu. The repository includes: - A Python script (exploit.py) for automated exploitation, supporting both single and mass URL targeting, with interactive shell capabilities for post-exploitation command execution. - A Metasploit module (spip_porte_plume_previsu_rce.rb) enabling customizable payload delivery, including Meterpreter reverse shells, and automated version checking. - Docker Compose files and documentation for setting up a vulnerable SPIP environment for testing. The main attack vector is network-based, targeting the web application endpoint. The exploit is highly operational and weaponized, supporting both command execution and reverse shell payloads. The endpoints of interest are /spip.php?action=porte_plume_previsu for exploitation and the Docker image ipeos/spip:4.2.12 for local testing. The exploit is not a detection script but a full RCE tool, and is part of the Metasploit framework, making it easily customizable and deployable.
This repository provides an operational exploit for CVE-2024-7954, a pre-authentication remote code execution (RCE) vulnerability in SPIP version 4.2.8. The main script, 'CVE-2024-7954.py', is a Python tool that allows users to target a single URL or a list of URLs (bulk mode) and execute arbitrary system commands on vulnerable SPIP installations. The exploit works by sending a specially crafted POST request to the '/index.php?action=porte_plume_previsu' endpoint, injecting PHP code that executes the supplied command. The tool supports multithreaded scanning, logs results to 'logs/scan.log', and provides colored terminal output for clarity. The repository also includes a README.md with usage instructions and a requirements.txt listing dependencies ('argparse' and 'requests'). The exploit is operational, providing real command execution on the target if successful, and is intended for use only on systems where the user has authorization.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.