Products: 1
    Vulnerabilities: 14
    Known Exploited: 0
    2
    Critical Level Threats
    6
    High Level Threats
    5
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2014-5083

    A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5083 pertains to instances of fwrite in Sphider.

    Last Modified: Nov 21, 2024
    Published: Feb 10, 2020

    CVE-2014-5086

    A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5086 pertains to instances of fwrite in Sphider Pro and Sphider Plus only, but don’t exist in Sphider.

    Last Modified: Nov 21, 2024
    Published: Feb 10, 2020

    CVE-2014-5087

    A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.

    Last Modified: Nov 21, 2024
    Published: Feb 07, 2020

    CVE-2014-5081

    sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass

    Last Modified: Nov 21, 2024
    Published: Jan 10, 2020

    CVE-2014-5193

    Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the category parameter. NOTE: the url parameter vector is already covered by CVE-2014-5082.

    Last Modified: Apr 12, 2025
    Published: Aug 07, 2014
    Items Per Page
    Sphider Vulnerabilities & Security CVEs | CVE-DB