Vulnerability Details CVE-2014-5082
Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers to execute arbitrary SQL commands via the (1) site_id or (2) url parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.024
EPSS Ranking 84.5%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2014-5082
-
cpe:2.3:a:sphider:sphider:1.3.2
-
cpe:2.3:a:sphider:sphider:1.3.3
-
cpe:2.3:a:sphider:sphider:1.3.4
-
cpe:2.3:a:sphider:sphider:1.3.5
-
cpe:2.3:a:sphider:sphider:1.3.6