Sphider Pro
Vendor:
First CVE: Jan 10, 2020 · Active for 6 years
4
Total CVEs
More Total CVEs than 75% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
9.3
Avg CVSS
Higher Avg CVSS than 86% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Sphider Pro over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2020
6 years ago
Most Recent CVE
Feb 10, 2020
2,360 days ago
CVE Severity & Scoring
Sphider Pro4 CVEs
50%
50%
All CVEs353,173 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (50.0%)
High0 (0.0%)
None2 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5081CRITICAL sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass | Jan 10, 2020 | 9.8 | 45 | NO | YES |
CVE-2014-5087CRITICAL A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code. | Feb 7, 2020 | 9.8 | 44 | NO | YES |
CVE-2014-5086HIGH A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execut | Feb 10, 2020 | 8.8 | 42 | NO | YES |
CVE-2014-5084HIGH A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious user execute arbitrary code. CVE-2014-508 | Feb 10, 2020 | 8.8 | 39 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
100.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Sphider Pro
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2 | 1 | 8.8 | 7.7% | 0 | 1 |