Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dotclear vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-3781
The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear prior to 2.6.3 allows remote malicious users to bypass authentication via an empty password in an XML-RPC request.
Dotclear Dotclear
Dotclear Dotclear 2.6.1
Dotclear Dotclear 2.6
NA
CVE-2011-5083
Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote malicious users to execute arbitrary code by uploading a file with an executable PHP extension, then accessing it via a direct request to the file in an unspecified directory...
Dotclear Dotclear 2.4.2
Dotclear Dotclear 2.3.1
NA
CVE-2005-3963
SQL injection vulnerability in session.php in DotClear prior to 1.2.3 allows remote malicious users to execute arbitrary SQL commands via the dc_xd parameter in a cookie.
Dotclear Dotclear 1.2.1
Dotclear Dotclear 1.2.2
1 EDB exploit
6.1
CVSSv3
CVE-2016-6523
Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear prior to 2.10 allow remote malicious users to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter to admin/media.php.
Dotclear Dotclear
8.8
CVSSv3
CVE-2015-8832
Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear prior to 2.8.2 allow remote authenticated users with "manage their own media items" and "manage their own entries and comments" permissions to execute arbitrary PHP code by...
Dotclear Dotclear
5.4
CVSSv3
CVE-2018-16358
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear up to and including 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.
Dotclear Dotclear
5.4
CVSSv3
CVE-2016-9891
Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear prior to 2.11 allows remote authenticated users to inject arbitrary web script or HTML via the upfiletitle or media_title parameter (aka the media title).
Dotclear Dotclear
7.2
CVSSv3
CVE-2016-9268
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear up to and including 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, a...
Dotclear Dotclear
NA
CVE-2007-1989
Multiple cross-site scripting (XSS) vulnerabilities in DotClear prior to 1.2.6 allow remote malicious users to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php. NOTE: some of these ...
Dotclear Dotclear
2 EDB exploits
NA
CVE-2015-5651
Cross-site scripting (XSS) vulnerability in Dotclear prior to 2.8.1 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Dotclear Dotclear
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-26978
CVE-2024-26982
wireless
CVE-2023-6949
CVE-2024-26980
CVE-2024-32766
CVE-2024-26939
cache poisoning
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »