sphider-plus kayıtları
sphider-plus üreticisine ait 4 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
4 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2014-5081Kavram kanıtı | sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypasssphider · sphider · CWE-287 | Kritik9,8 | — | %10,5 | 10 Oca 2020 |
41Planlayın | CVE-2014-5087Kavram kanıtı | A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciousphider · sphider · CWE-20 | Kritik9,8 | — | %7,2 | 7 Şub 2020 |
38İzleyin | CVE-2014-5086Kavram kanıtı | A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which sphider · sphider · CWE-74 | Yüksek8,8 | — | %9,8 | 10 Şub 2020 |
37İzleyin | CVE-2014-5085Kavram kanıtı | A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remotsphider-plus · sphider-plus · CWE-74 | Yüksek8,8 | — | %5,8 | 10 Şub 2020 |
- CVE-2014-508142Planlayın
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
KritikCVSS 9,8Kavram kanıtıEPSS %10sphider · sphider10 Oca 2020
- CVE-2014-508741Planlayın
A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote maliciou
KritikCVSS 9,8Kavram kanıtıEPSS %7sphider · sphider7 Şub 2020
- CVE-2014-508638İzleyin
A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which
YüksekCVSS 8,8Kavram kanıtıEPSS %10sphider · sphider10 Şub 2020
- CVE-2014-508537İzleyin
A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remot
YüksekCVSS 8,8Kavram kanıtıEPSS %6sphider-plus · sphider-plus10 Şub 2020