Show filters
87 Total Results
Displaying 31-40 of 87
Sort by:
Attacker Value
Unknown

CVE-2015-5651

Disclosure Date: October 03, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Dotclear before 2.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-6722

Disclosure Date: September 26, 2014 (last updated October 05, 2023)
The Pescuit Crap Lite (aka ro.aventurilapescui.pescuitcrap.lite) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-6720

Disclosure Date: September 26, 2014 (last updated October 05, 2023)
The Pesca de Carpa Lite (aka com.clearfishing.pescadecarpa.lite) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-5316

Disclosure Date: September 22, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Dotclear before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted page.
0
Attacker Value
Unknown

CVE-2014-5854

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Windows Live Hotmail PUSH mail (aka com.clearhub.wl) application 1.00.97 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-3782

Disclosure Date: June 11, 2014 (last updated October 05, 2023)
Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some other PHP file extension.
0
Attacker Value
Unknown

CVE-2014-3781

Disclosure Date: June 11, 2014 (last updated October 05, 2023)
The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty password in an XML-RPC request.
0
Attacker Value
Unknown

CVE-2014-3783

Disclosure Date: May 22, 2014 (last updated October 05, 2023)
SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission to execute arbitrary SQL commands via the categories_order parameter.
0
Attacker Value
Unknown

CVE-2014-1613

Disclosure Date: May 16, 2014 (last updated October 05, 2023)
Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public.php.
0
Attacker Value
Unknown

CVE-2012-1039

Disclosure Date: March 19, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) order, or (6) status parameters to admin/comments.php; or (7) page parameter to admin/plugin.php.
0