CVE-2014-5194: Sphider
Medium severity, CVSS 6.5. EPSS: 4.2% chance of exploitation in the next 30 days.
Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/conf.php via the _word_upper_bound parameter.
Affected products
- Sphider Sphider: version 1.3.6 only
Published 2014-08-07. Last modified 2026-06-17.