Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

CVE-2016-9268

Disclosure Date: November 10, 2016 (last updated November 25, 2024)
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-5651

Disclosure Date: October 03, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Dotclear before 2.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-5316

Disclosure Date: September 22, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Dotclear before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted page.
0
Attacker Value
Unknown

CVE-2014-3782

Disclosure Date: June 11, 2014 (last updated October 05, 2023)
Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some other PHP file extension.
0
Attacker Value
Unknown

CVE-2014-3781

Disclosure Date: June 11, 2014 (last updated October 05, 2023)
The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty password in an XML-RPC request.
0
Attacker Value
Unknown

CVE-2014-3783

Disclosure Date: May 22, 2014 (last updated October 05, 2023)
SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission to execute arbitrary SQL commands via the categories_order parameter.
0
Attacker Value
Unknown

CVE-2014-1613

Disclosure Date: May 16, 2014 (last updated October 05, 2023)
Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public.php.
0
Attacker Value
Unknown

CVE-2012-1039

Disclosure Date: March 19, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.
0
Attacker Value
Unknown

CVE-2011-5083

Disclosure Date: March 19, 2012 (last updated October 04, 2023)
Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uploading a file with an executable PHP extension, then accessing it via a direct request to the file in an unspecified directory.
0
Attacker Value
Unknown

CVE-2011-1584

Disclosure Date: June 08, 2011 (last updated October 04, 2023)
The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, which allows remote authenticated users to upload and execute arbitrary PHP code via the media_path or media_file parameter. NOTE: some of these details are obtained from third party information.
0