CVE-2014-5082
06.08.2014, 18:55
Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers to execute arbitrary SQL commands via the (1) site_id or (2) url parameter.
| Vendor | Product | Version |
|---|---|---|
| sphider | sphider | 𝑥 ≤ 1.3.6 |
| sphider | sphider | 1.3.2 |
| sphider | sphider | 1.3.3 |
| sphider | sphider | 1.3.4 |
| sphider | sphider | 1.3.4:b |
| sphider | sphider | 1.3.5 |
𝑥
= Vulnerable software versions