cpe:/a:spip:spip:3.1.0 cpe:/a:spip:spip:3.1.0:alpha cpe:/a:spip:spip:3.1.0:beta cpe:/a:spip:spip:3.1.0:rc cpe:/a:spip:spip:3.1.0:rc2 cpe:/a:spip:spip:3.1.0:rc3 cpe:/a:spip:spip:3.1.1 cpe:/a:spip:spip:3.1.2 cpe:/a:spip:spip:3.1.3 cpe:/a:spip:spip:3.1.4 cpe:/a:spip:spip:3.1.5 cpe:/a:spip:spip:3.2:alpha-1 cpe:/a:spip:spip:3.2.0:beta cpe:/a:spip:spip:3.2.0:beta2 CVE-2017-9736 2017-06-17T12:29:00.180-04:00 2017-11-03T21:29:57.180-04:00 7.5 NETWORK LOW NONE PARTIAL PARTIAL PARTIAL http://nvd.nist.gov DEBIAN DSA-3890 CONFIRM https://contrib.spip.net/CRITICAL-security-update-SPIP-3-1-6-and-SPIP-3-2-Beta CONFIRM https://core.spip.net/projects/spip/repository/revisions/23593 CONFIRM https://core.spip.net/projects/spip/repository/revisions/23594 SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution.