Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sphider HIGH 8.8
CVE-2014-5086EPSS 10%

A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let…

Fix: 1.3.6 / 3.2+
Fix from $1,950 2020-02-10
Sphider HIGH 8.8
CVE-2014-5083EPSS 6%

A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a remote mal…

Fix: 1.3.6+
Fix from $1,950 2020-02-10
Sphider CRITICAL 9.8
CVE-2014-5087EPSS 7%

A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user ex…

Fix: 1.3.6 / 3.2+
Fix from $2,300 2020-02-07
Sphider CRITICAL 9.8
CVE-2014-5081EPSS 10%

sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass

Fix: 1.3.6 / 3.2+
Fix from $2,300 2020-01-10
Sphider HIGH 7.5
CVE-2014-5192

SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter parameter.

No fix yet
Fix from $1,950 2014-08-07
Sphider MEDIUM 6.5
CVE-2014-5194

Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/…

No fix yet
Fix from $1,600 2014-08-07
Sphider HIGH 7.5
CVE-2014-5082

Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers to execu…

Fix: after 1.3.6
Fix from $1,950 2014-08-06
Sphider HIGH 7.5
CVE-2007-2411

PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the include_…

Fix: after 1.2.7
Fix from $1,950 2007-05-01
Sphider HIGH 7.5
CVE-2006-7057

SQL injection vulnerability in search.php in Sphider before 1.3.1c allows remote attackers to execute arbitrary SQL commands via the category paramet…

Fix: after 1.3b
Fix from $1,950 2007-02-24
Sphider MEDIUM 6.8
CVE-2006-2506

Multiple cross-site scripting (XSS) vulnerabilities in search.php in Sphider allow remote attackers to inject arbitrary web script or HTML via (1) th…

No fix yet
Fix from $1,600 2006-05-22
Sphider MEDIUM 5.1
CVE-2006-1784EPSS 8%

PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers…

No fix yet
Fix from $1,600 2006-04-13