sphider kayıtları
sphider üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2014-5081Kavram kanıtı | sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypasssphider · sphider · CWE-287 | Kritik9,8 | — | %10,5 | 10 Oca 2020 |
41Planlayın | CVE-2014-5087Kavram kanıtı | A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciousphider · sphider · CWE-20 | Kritik9,8 | — | %7,2 | 7 Şub 2020 |
38İzleyin | CVE-2014-5086Kavram kanıtı | A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which sphider · sphider · CWE-74 | Yüksek8,8 | — | %9,8 | 10 Şub 2020 |
37İzleyin | CVE-2014-5083Kavram kanıtı | A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a rsphider · sphider · CWE-74 | Yüksek8,8 | — | %5,8 | 10 Şub 2020 |
31İzleyin | CVE-2007-2411İstismar yok | PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in thesphider · sphider | Yüksek7,5 | — | %2,7 | 1 May 2007 |
31İzleyin | CVE-2014-5082Kavram kanıtı | Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackerssphider · sphider · CWE-89 | Yüksek7,5 | — | %2,1 | 6 Ağu 2014 |
30İzleyin | CVE-2014-5192Kavram kanıtı | SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter parsphider · sphider · CWE-89 | Yüksek7,5 | — | %1,2 | 7 Ağu 2014 |
30İzleyin | CVE-2006-7057İstismar yok | SQL injection vulnerability in search.php in Sphider before 1.3.1c allows remote attackers to execute arbitrary SQL commands via the categorsphider · sphider | Yüksek7,5 | — | %1,1 | 23 Şub 2007 |
27İzleyin | CVE-2014-5194Kavram kanıtı | Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into sphider · sphider · CWE-94 | Orta6,5 | — | %4,2 | 7 Ağu 2014 |
27İzleyin | CVE-2006-2506İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in search.php in Sphider allow remote attackers to inject arbitrary web script or HTML vsphider · sphider · CWE-79 | Orta6,8 | — | %1,6 | 22 May 2006 |
22İzleyin | CVE-2006-1784Kavram kanıtı | PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote sphider · sphider | Orta5,1 | — | %7,8 | 13 Nis 2006 |
18İzleyin | CVE-2014-5193Kavram kanıtı | Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML sphider · sphider · CWE-79 | Orta4,3 | — | %1,8 | 7 Ağu 2014 |
17İzleyin | CVE-2006-7058İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in Sphider before 1.3.1c allow remote attackers to inject arbitrary web script or HTML vsphider · sphider | Orta4,3 | — | %1,1 | 23 Şub 2007 |
11İzleyin | CVE-2008-5211Kavram kanıtı | Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attacksphider · sphider · CWE-79 | Düşük2,6 | — | %1,8 | 24 Kas 2008 |
- CVE-2014-508142Planlayın
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
KritikCVSS 9,8Kavram kanıtıEPSS %10sphider · sphider10 Oca 2020
- CVE-2014-508741Planlayın
A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciou
KritikCVSS 9,8Kavram kanıtıEPSS %7sphider · sphider7 Şub 2020
- CVE-2014-508638İzleyin
A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which
YüksekCVSS 8,8Kavram kanıtıEPSS %10sphider · sphider10 Şub 2020
- CVE-2014-508337İzleyin
A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a r
YüksekCVSS 8,8Kavram kanıtıEPSS %6sphider · sphider10 Şub 2020
- CVE-2007-241131İzleyin
PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the
YüksekCVSS 7,5İstismar yokEPSS %3sphider · sphider1 May 2007
- CVE-2014-508231İzleyin
Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers
YüksekCVSS 7,5Kavram kanıtıEPSS %2sphider · sphider6 Ağu 2014
- CVE-2014-519230İzleyin
SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter par
YüksekCVSS 7,5Kavram kanıtıEPSS %1sphider · sphider7 Ağu 2014
- CVE-2006-705730İzleyin
SQL injection vulnerability in search.php in Sphider before 1.3.1c allows remote attackers to execute arbitrary SQL commands via the categor
YüksekCVSS 7,5İstismar yokEPSS %1sphider · sphider23 Şub 2007
- CVE-2014-519427İzleyin
Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into
OrtaCVSS 6,5Kavram kanıtıEPSS %4sphider · sphider7 Ağu 2014
- CVE-2006-250627İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in search.php in Sphider allow remote attackers to inject arbitrary web script or HTML v
OrtaCVSS 6,8İstismar yokEPSS %2sphider · sphider22 May 2006
- CVE-2006-178422İzleyin
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote
OrtaCVSS 5,1Kavram kanıtıEPSS %8sphider · sphider13 Nis 2006
- CVE-2014-519318İzleyin
Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML
OrtaCVSS 4,3Kavram kanıtıEPSS %2sphider · sphider7 Ağu 2014
- CVE-2006-705817İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Sphider before 1.3.1c allow remote attackers to inject arbitrary web script or HTML v
OrtaCVSS 4,3İstismar yokEPSS %1sphider · sphider23 Şub 2007
- CVE-2008-521111İzleyin
Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled, allows remote attack
DüşükCVSS 2,6Kavram kanıtıEPSS %2sphider · sphider24 Kas 2008