CVE-2014-5085
HIGHSphider Plus 3.2 - Remote Code Execution via fwrite to conf.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-5085.
AI-analyzed exploit summary The document provides a detailed technical analysis of multiple vulnerabilities in Sphider Search Engine, including authentication bypass, SQL injection, and remote code execution (RCE). It includes proof-of-concept (PoC) commands and code snippets demonstrating the exploitation of these vulnerabilities.
Description
A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5085 pertains to instances of fwrite in Sphider Plus, but do not exist in either Sphider or Sphider Pro.
Exploits (1)
The document provides a detailed technical analysis of multiple vulnerabilities in Sphider Search Engine, including authentication bypass, SQL injection, and remote code execution (RCE). It includes proof-of-concept (PoC) commands and code snippets demonstrating the exploitation of these vulnerabilities.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H