NA
CVSSv4

CVE-2014-5083

CVSSv4: NA | CVSSv3: 8.8 | CVSSv2: 6.5 | VMScore: 980 | EPSS: 0.06355 | KEV: Not Included
Published: 10/02/2020 Updated: 21/11/2024

Vulnerability Summary

A Command Execution vulnerability exists in Sphider prior to 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5083 pertains to instances of fwrite in Sphider.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sphider sphider

Exploits

Sphider versions prior to 136 suffer from remote command execution and remote SQL injection vulnerabilities ...
# Exploit Title: Sphider Search Engine - Multiple Vulnerabilities # Google Dork: ext:php intext:sphider inurl:searchphp # Date: 6/20/2014 # Exploit Author: Shayan Sadigh (twittercom/r1pplex) | <ienjoyripples@gmailcom> # Vendor Homepage: wwwsphidereu/ # Version: Sphider < 136 | Sphider Pro/Plus as well # Tested on: Linux &amp ...