NA
CVSSv4

CVE-2014-5084

CVSSv4: NA | CVSSv3: 8.8 | CVSSv2: 6.5 | VMScore: 980 | EPSS: 0.00602 | KEV: Not Included
Published: 10/02/2020 Updated: 21/11/2024

Vulnerability Summary

A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious user execute arbitrary code. CVE-2014-5084 pertains to instances of fwrite in Sphider Pro only, but do not exist in either Sphider or Sphider Plus.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sphiderpro sphider pro 3.2

Exploits

# Exploit Title: Sphider Search Engine - Multiple Vulnerabilities # Google Dork: ext:php intext:sphider inurl:searchphp # Date: 6/20/2014 # Exploit Author: Shayan Sadigh (twittercom/r1pplex) | <ienjoyripples@gmailcom> # Vendor Homepage: wwwsphidereu/ # Version: Sphider < 136 | Sphider Pro/Plus as well # Tested on: Linux &amp ...
Sphider versions prior to 136 suffer from remote command execution and remote SQL injection vulnerabilities ...