Записи sphider
14 опубликованных записей вендора sphider.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2014-5081Proof of concept | sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypasssphider · sphider · CWE-287 | Критическая9,8 | — | 10,5 % | 10 янв. 2020 г. |
41В плане | CVE-2014-5087Proof of concept | A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciousphider · sphider · CWE-20 | Критическая9,8 | — | 7,2 % | 7 февр. 2020 г. |
38Наблюдать | CVE-2014-5086Proof of concept | A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which sphider · sphider · CWE-74 | Высокая8,8 | — | 9,8 % | 10 февр. 2020 г. |
37Наблюдать | CVE-2014-5083Proof of concept | A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a rsphider · sphider · CWE-74 | Высокая8,8 | — | 5,8 % | 10 февр. 2020 г. |
31Наблюдать | CVE-2007-2411Эксплойта нет | PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in thesphider · sphider | Высокая7,5 | — | 2,7 % | 1 мая 2007 г. |
31Наблюдать | CVE-2014-5082Proof of concept | Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackerssphider · sphider · CWE-89 | Высокая7,5 | — | 2,1 % | 6 авг. 2014 г. |
30Наблюдать | CVE-2014-5192Proof of concept | SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter parsphider · sphider · CWE-89 | Высокая7,5 | — | 1,2 % | 7 авг. 2014 г. |
30Наблюдать | CVE-2006-7057Эксплойта нет | SQL injection vulnerability in search.php in Sphider before 1.3.1c allows remote attackers to execute arbitrary SQL commands via the categorsphider · sphider | Высокая7,5 | — | 1,1 % | 23 февр. 2007 г. |
27Наблюдать | CVE-2014-5194Proof of concept | Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into sphider · sphider · CWE-94 | Средняя6,5 | — | 4,2 % | 7 авг. 2014 г. |
27Наблюдать | CVE-2006-2506Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in search.php in Sphider allow remote attackers to inject arbitrary web script or HTML vsphider · sphider · CWE-79 | Средняя6,8 | — | 1,6 % | 22 мая 2006 г. |
22Наблюдать | CVE-2006-1784Proof of concept | PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote sphider · sphider | Средняя5,1 | — | 7,8 % | 13 апр. 2006 г. |
18Наблюдать | CVE-2014-5193Proof of concept | Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML sphider · sphider · CWE-79 | Средняя4,3 | — | 1,8 % | 7 авг. 2014 г. |
17Наблюдать | CVE-2006-7058Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in Sphider before 1.3.1c allow remote attackers to inject arbitrary web script or HTML vsphider · sphider | Средняя4,3 | — | 1,1 % | 23 февр. 2007 г. |
11Наблюдать | CVE-2008-5211Proof of concept | Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attacksphider · sphider · CWE-79 | Низкая2,6 | — | 1,8 % | 24 нояб. 2008 г. |
- CVE-2014-508142В плане
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
КритическаяCVSS 9,8Proof of conceptEPSS 10 %sphider · sphider10 янв. 2020 г.
- CVE-2014-508741В плане
A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciou
КритическаяCVSS 9,8Proof of conceptEPSS 7 %sphider · sphider7 февр. 2020 г.
- CVE-2014-508638Наблюдать
A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which
ВысокаяCVSS 8,8Proof of conceptEPSS 10 %sphider · sphider10 февр. 2020 г.
- CVE-2014-508337Наблюдать
A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a r
ВысокаяCVSS 8,8Proof of conceptEPSS 6 %sphider · sphider10 февр. 2020 г.
- CVE-2007-241131Наблюдать
PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %sphider · sphider1 мая 2007 г.
- CVE-2014-508231Наблюдать
Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %sphider · sphider6 авг. 2014 г.
- CVE-2014-519230Наблюдать
SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter par
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %sphider · sphider7 авг. 2014 г.
- CVE-2006-705730Наблюдать
SQL injection vulnerability in search.php in Sphider before 1.3.1c allows remote attackers to execute arbitrary SQL commands via the categor
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sphider · sphider23 февр. 2007 г.
- CVE-2014-519427Наблюдать
Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into
СредняяCVSS 6,5Proof of conceptEPSS 4 %sphider · sphider7 авг. 2014 г.
- CVE-2006-250627Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in search.php in Sphider allow remote attackers to inject arbitrary web script or HTML v
СредняяCVSS 6,8Эксплойта нетEPSS 2 %sphider · sphider22 мая 2006 г.
- CVE-2006-178422Наблюдать
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote
СредняяCVSS 5,1Proof of conceptEPSS 8 %sphider · sphider13 апр. 2006 г.
- CVE-2014-519318Наблюдать
Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML
СредняяCVSS 4,3Proof of conceptEPSS 2 %sphider · sphider7 авг. 2014 г.
- CVE-2006-705817Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Sphider before 1.3.1c allow remote attackers to inject arbitrary web script or HTML v
СредняяCVSS 4,3Эксплойта нетEPSS 1 %sphider · sphider23 февр. 2007 г.
- CVE-2008-521111Наблюдать
Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attack
НизкаяCVSS 2,6Proof of conceptEPSS 2 %sphider · sphider24 нояб. 2008 г.