cve/2014/CVE-2014-5086.md
2024-05-26 14:27:05 +02:00

834 B
Raw Blame History

CVE-2014-5086

Description

A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5086 pertains to instances of fwrite in Sphider Pro and Sphider Plus only, but dont exist in Sphider.

POC

Reference

Github

No PoCs found on GitHub currently.