Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-5192. PoCs published by Mike Manzotti.
AI-analyzed exploit summary The exploit demonstrates SQL injection, PHP code injection (RCE), and XSS vulnerabilities in Sphider 1.3.6. It includes proof-of-concept payloads for each vulnerability type, with clear examples of malicious input and expected responses.
Description
SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter parameter.
Exploits (1)
The exploit demonstrates SQL injection, PHP code injection (RCE), and XSS vulnerabilities in Sphider 1.3.6. It includes proof-of-concept payloads for each vulnerability type, with clear examples of malicious input and expected responses.