cbcvebase.

Sphiderpro Sphider Pro vulnerabilities

4 known vulnerabilities affecting sphiderpro/sphider_pro.

Total CVEs
4
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2

Vulnerabilities

Page 1 of 1
CVE-2014-5081P2CRITICALCVSS 9.8PoCfixed in 3.22020-01-10
CVE-2014-5081 [CRITICAL] CWE-287 CVE-2014-5081: sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
nvd
CVE-2014-5086P2HIGHCVSS 8.8PoCfixed in 3.22020-02-10
CVE-2014-5086 [HIGH] CWE-74 CVE-2014-5086: A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sa A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5086 pertains to instances of fwrite in Sphider Pro and Sphider Plus only, but don’t exist in Sphider.
nvd
CVE-2014-5087P2CRITICALCVSS 9.8PoCfixed in 3.22020-02-07
CVE-2014-5087 [CRITICAL] CWE-20 CVE-2014-5087: A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfunc A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.
nvd
CVE-2014-5084P2HIGHCVSS 8.8PoCv3.22020-02-10
CVE-2014-5084 [HIGH] CWE-74 CVE-2014-5084: A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwri A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious user execute arbitrary code. CVE-2014-5084 pertains to instances of fwrite in Sphider Pro only, but do not exist in either Sphider or Sphider Plus.
nvd
Sphiderpro Sphider Pro vulnerabilities | cvebase