Description
This module exploits an unauthenticated RCE in SPIP <= 4.4.21 via the forum autosave session handler. The action=session endpoint allows any visitor to store arbitrary data in a PHP session variable. By writing PHP code into an autosave_forum_* session key, the code is executed by the template engine when the forum form page is rendered with the poisoned session.
Requires a published article with public forums enabled.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/http/spip/autosave_rcemsf undefined(autosave_rce) > show actions ...actions...msf undefined(autosave_rce) > set ACTION < action-name >msf undefined(autosave_rce) > show options ...show and set options...msf undefined(autosave_rce) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub