CVE-2014-5194
Sphider 1.3.6 - Authenticated PHP Code Injection via _word_upper_bound Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-5194. PoCs published by Mike Manzotti.
AI-analyzed exploit summary The exploit demonstrates SQL injection, PHP code injection (RCE), and XSS vulnerabilities in Sphider 1.3.6. It includes proof-of-concept payloads for each vulnerability type, with clear examples of malicious input and expected responses.
Description
Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/conf.php via the _word_upper_bound parameter.
Exploits (1)
The exploit demonstrates SQL injection, PHP code injection (RCE), and XSS vulnerabilities in Sphider 1.3.6. It includes proof-of-concept payloads for each vulnerability type, with clear examples of malicious input and expected responses.