5.8
CVSSv2

CVE-2014-3781

Published: 11/06/2014 Updated: 12/06/2014
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear prior to 2.6.3 allows remote malicious users to bypass authentication via an empty password in an XML-RPC request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dotclear dotclear

dotclear dotclear 2.6.1

dotclear dotclear 2.6

Exploits

Dotclear versions 262 and below suffer from an XML-RPC interface authentication bypass vulnerability ...