vendor:
Sphider Search Engine
by:
Gurkirat Singh
9.8
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Sphider Search Engine
Affected Version From: 1.3.6
Affected Version To: 1.3.6
Patch Exists: YES
Related CWE: CVE-2014-5194
CPE: a:sphider:sphider:1.3.6
Metasploit:
https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-7702/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-7703/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2015-5219/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2015-7701/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-7701/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-7852/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2015-7692/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-7702/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-5194/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-5219/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-7871/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-7703/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-5194/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-5195/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-5219/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-7691/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2015-5300/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2015-5300/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2015-7702/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2015-7692/, https://www.rapid7.com/db/?q=CVE-2014-5194&type=&page=2, https://www.rapid7.com/db/?q=CVE-2014-5194&type=&page=3, https://www.rapid7.com/db/?q=CVE-2014-5194&type=&page=2
Other Scripts:
N/A
Platforms Tested: Windows and Linux
2014
Sphider Search Engine 1.3.6 – ‘word_upper_bound’ RCE (Authenticated)
Sphider Search Engine version 1.3.6 is vulnerable to a Remote Code Execution vulnerability due to improper input validation of the 'word_upper_bound' parameter. An authenticated attacker can exploit this vulnerability to execute arbitrary code on the vulnerable system.
Mitigation:
Upgrade to the latest version of Sphider Search Engine.