Vulnerability Details CVE-2006-1784
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings_dir parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.072
EPSS Ranking 91.3%
CVSS Severity
CVSS v2 Score 5.1
Products affected by CVE-2006-1784
-
cpe:2.3:a:sphider:sphider:1.3
-
cpe:2.3:a:sphider:sphider:1.3_rc1
-
cpe:2.3:a:sphider:sphider:1.3_rc2