sphiderpro records
4 published records for vendor sphiderpro.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2014-5081Proof of concept | sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypasssphider · sphider · CWE-287 | Critical9.8 | — | 10.5% | Jan 10, 2020 |
41Plan | CVE-2014-5087Proof of concept | A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciousphider · sphider · CWE-20 | Critical9.8 | — | 7.2% | Feb 7, 2020 |
38Monitor | CVE-2014-5086Proof of concept | A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which sphider · sphider · CWE-74 | High8.8 | — | 9.8% | Feb 10, 2020 |
37Monitor | CVE-2014-5084Proof of concept | A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious usphiderpro · sphider pro · CWE-74 | High8.8 | — | 7.7% | Feb 10, 2020 |
- CVE-2014-508142Plan
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
CriticalCVSS 9.8Proof of conceptEPSS 10%sphider · sphiderJan 10, 2020
- CVE-2014-508741Plan
A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciou
CriticalCVSS 9.8Proof of conceptEPSS 7%sphider · sphiderFeb 7, 2020
- CVE-2014-508638Monitor
A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which
HighCVSS 8.8Proof of conceptEPSS 10%sphider · sphiderFeb 10, 2020
- CVE-2014-508437Monitor
A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious u
HighCVSS 8.8Proof of conceptEPSS 8%sphiderpro · sphider proFeb 10, 2020