sphider records
14 published records for vendor sphider.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2014-5081Proof of concept | sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypasssphider · sphider · CWE-287 | Critical9.8 | — | 10.5% | Jan 10, 2020 |
41Plan | CVE-2014-5087Proof of concept | A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciousphider · sphider · CWE-20 | Critical9.8 | — | 7.2% | Feb 7, 2020 |
38Monitor | CVE-2014-5086Proof of concept | A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which sphider · sphider · CWE-74 | High8.8 | — | 9.8% | Feb 10, 2020 |
37Monitor | CVE-2014-5083Proof of concept | A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a rsphider · sphider · CWE-74 | High8.8 | — | 5.8% | Feb 10, 2020 |
31Monitor | CVE-2007-2411No exploit | PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in thesphider · sphider | High7.5 | — | 2.7% | May 1, 2007 |
31Monitor | CVE-2014-5082Proof of concept | Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackerssphider · sphider · CWE-89 | High7.5 | — | 2.1% | Aug 6, 2014 |
30Monitor | CVE-2014-5192Proof of concept | SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter parsphider · sphider · CWE-89 | High7.5 | — | 1.2% | Aug 7, 2014 |
30Monitor | CVE-2006-7057No exploit | SQL injection vulnerability in search.php in Sphider before 1.3.1c allows remote attackers to execute arbitrary SQL commands via the categorsphider · sphider | High7.5 | — | 1.1% | Feb 23, 2007 |
27Monitor | CVE-2014-5194Proof of concept | Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into sphider · sphider · CWE-94 | Medium6.5 | — | 4.2% | Aug 7, 2014 |
27Monitor | CVE-2006-2506No exploit | Multiple cross-site scripting (XSS) vulnerabilities in search.php in Sphider allow remote attackers to inject arbitrary web script or HTML vsphider · sphider · CWE-79 | Medium6.8 | — | 1.6% | May 22, 2006 |
22Monitor | CVE-2006-1784Proof of concept | PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote sphider · sphider | Medium5.1 | — | 7.8% | Apr 13, 2006 |
18Monitor | CVE-2014-5193Proof of concept | Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML sphider · sphider · CWE-79 | Medium4.3 | — | 1.8% | Aug 7, 2014 |
17Monitor | CVE-2006-7058No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Sphider before 1.3.1c allow remote attackers to inject arbitrary web script or HTML vsphider · sphider | Medium4.3 | — | 1.1% | Feb 23, 2007 |
11Monitor | CVE-2008-5211Proof of concept | Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attacksphider · sphider · CWE-79 | Low2.6 | — | 1.8% | Nov 24, 2008 |
- CVE-2014-508142Plan
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
CriticalCVSS 9.8Proof of conceptEPSS 10%sphider · sphiderJan 10, 2020
- CVE-2014-508741Plan
A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciou
CriticalCVSS 9.8Proof of conceptEPSS 7%sphider · sphiderFeb 7, 2020
- CVE-2014-508638Monitor
A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which
HighCVSS 8.8Proof of conceptEPSS 10%sphider · sphiderFeb 10, 2020
- CVE-2014-508337Monitor
A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a r
HighCVSS 8.8Proof of conceptEPSS 6%sphider · sphiderFeb 10, 2020
- CVE-2007-241131Monitor
PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the
HighCVSS 7.5No exploitEPSS 3%sphider · sphiderMay 1, 2007
- CVE-2014-508231Monitor
Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers
HighCVSS 7.5Proof of conceptEPSS 2%sphider · sphiderAug 6, 2014
- CVE-2014-519230Monitor
SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter par
HighCVSS 7.5Proof of conceptEPSS 1%sphider · sphiderAug 7, 2014
- CVE-2006-705730Monitor
SQL injection vulnerability in search.php in Sphider before 1.3.1c allows remote attackers to execute arbitrary SQL commands via the categor
HighCVSS 7.5No exploitEPSS 1%sphider · sphiderFeb 23, 2007
- CVE-2014-519427Monitor
Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into
MediumCVSS 6.5Proof of conceptEPSS 4%sphider · sphiderAug 7, 2014
- CVE-2006-250627Monitor
Multiple cross-site scripting (XSS) vulnerabilities in search.php in Sphider allow remote attackers to inject arbitrary web script or HTML v
MediumCVSS 6.8No exploitEPSS 2%sphider · sphiderMay 22, 2006
- CVE-2006-178422Monitor
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote
MediumCVSS 5.1Proof of conceptEPSS 8%sphider · sphiderApr 13, 2006
- CVE-2014-519318Monitor
Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML
MediumCVSS 4.3Proof of conceptEPSS 2%sphider · sphiderAug 7, 2014
- CVE-2006-705817Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Sphider before 1.3.1c allow remote attackers to inject arbitrary web script or HTML v
MediumCVSS 4.3No exploitEPSS 1%sphider · sphiderFeb 23, 2007
- CVE-2008-521111Monitor
Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attack
LowCVSS 2.6Proof of conceptEPSS 2%sphider · sphiderNov 24, 2008