Перейти к содержимому
Noroxi

Записи sphider

14 опубликованных записей вендора sphider.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
6
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

14 записей
  • CVE-2014-5081
    42В плане

    sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass

    КритическаяCVSS 9,8Proof of conceptEPSS 10 %

    sphider · sphider10 янв. 2020 г.

  • CVE-2014-5087
    41В плане

    A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciou

    КритическаяCVSS 9,8Proof of conceptEPSS 7 %

    sphider · sphider7 февр. 2020 г.

  • CVE-2014-5086
    38Наблюдать

    A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which

    ВысокаяCVSS 8,8Proof of conceptEPSS 10 %

    sphider · sphider10 февр. 2020 г.

  • CVE-2014-5083
    37Наблюдать

    A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a r

    ВысокаяCVSS 8,8Proof of conceptEPSS 6 %

    sphider · sphider10 февр. 2020 г.

  • CVE-2007-2411
    31Наблюдать

    PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    sphider · sphider1 мая 2007 г.

  • CVE-2014-5082
    31Наблюдать

    Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    sphider · sphider6 авг. 2014 г.

  • CVE-2014-5192
    30Наблюдать

    SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter par

    ВысокаяCVSS 7,5Proof of conceptEPSS 1 %

    sphider · sphider7 авг. 2014 г.

  • CVE-2006-7057
    30Наблюдать

    SQL injection vulnerability in search.php in Sphider before 1.3.1c allows remote attackers to execute arbitrary SQL commands via the categor

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    sphider · sphider23 февр. 2007 г.

  • CVE-2014-5194
    27Наблюдать

    Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into

    СредняяCVSS 6,5Proof of conceptEPSS 4 %

    sphider · sphider7 авг. 2014 г.

  • CVE-2006-2506
    27Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in search.php in Sphider allow remote attackers to inject arbitrary web script or HTML v

    СредняяCVSS 6,8Эксплойта нетEPSS 2 %

    sphider · sphider22 мая 2006 г.

  • CVE-2006-1784
    22Наблюдать

    PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote

    СредняяCVSS 5,1Proof of conceptEPSS 8 %

    sphider · sphider13 апр. 2006 г.

  • CVE-2014-5193
    18Наблюдать

    Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    sphider · sphider7 авг. 2014 г.

  • CVE-2006-7058
    17Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in Sphider before 1.3.1c allow remote attackers to inject arbitrary web script or HTML v

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    sphider · sphider23 февр. 2007 г.

  • CVE-2008-5211
    11Наблюдать

    Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attack

    НизкаяCVSS 2,6Proof of conceptEPSS 2 %

    sphider · sphider24 нояб. 2008 г.