Записи sphiderpro
4 опубликованных записей вендора sphiderpro.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2014-5081Proof of concept | sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypasssphider · sphider · CWE-287 | Критическая9,8 | — | 10,5 % | 10 янв. 2020 г. |
41В плане | CVE-2014-5087Proof of concept | A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciousphider · sphider · CWE-20 | Критическая9,8 | — | 7,2 % | 7 февр. 2020 г. |
38Наблюдать | CVE-2014-5086Proof of concept | A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which sphider · sphider · CWE-74 | Высокая8,8 | — | 9,8 % | 10 февр. 2020 г. |
37Наблюдать | CVE-2014-5084Proof of concept | A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious usphiderpro · sphider pro · CWE-74 | Высокая8,8 | — | 7,7 % | 10 февр. 2020 г. |
- CVE-2014-508142В плане
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
КритическаяCVSS 9,8Proof of conceptEPSS 10 %sphider · sphider10 янв. 2020 г.
- CVE-2014-508741В плане
A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciou
КритическаяCVSS 9,8Proof of conceptEPSS 7 %sphider · sphider7 февр. 2020 г.
- CVE-2014-508638Наблюдать
A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which
ВысокаяCVSS 8,8Proof of conceptEPSS 10 %sphider · sphider10 февр. 2020 г.
- CVE-2014-508437Наблюдать
A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious u
ВысокаяCVSS 8,8Proof of conceptEPSS 8 %sphiderpro · sphider pro10 февр. 2020 г.