Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-5194

Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/conf.php via the _word_upper_bound parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.026
EPSS Ranking 85.1%
CVSS Severity
CVSS v2 Score 6.5
Products affected by CVE-2014-5194
  • Sphider » Sphider » Version: 1.3.6
    cpe:2.3:a:sphider:sphider:1.3.6


Contact Us

Shodan ® - All rights reserved