6
CVSSv2

CVE-2014-3783

Published: 22/05/2014 Updated: 09/10/2018
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in admin/categories.php in Dotclear prior to 2.6.3 allows remote authenticated users with the manage categories permission to execute arbitrary SQL commands via the categories_order parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dotclear dotclear 2.6

dotclear dotclear 2.5.3

dotclear dotclear 2.3.1

dotclear dotclear 2.3.0

dotclear dotclear 2.1.4

dotclear dotclear 2.1.3

dotclear dotclear 2.0

dotclear dotclear 1.2.8

dotclear dotclear 1.2.7

dotclear dotclear

dotclear dotclear 2.5.0

dotclear dotclear 2.4.4

dotclear dotclear 2.2.1

dotclear dotclear 2.2

dotclear dotclear 2.0.2

dotclear dotclear 2.0.1

dotclear dotclear 1.2.4

dotclear dotclear 1.2.3

dotclear dotclear 2.6.1

dotclear dotclear 2.4.3

dotclear dotclear 2.4.2

dotclear dotclear 2.1.7

dotclear dotclear 2.1.6

dotclear dotclear 2.1.5

dotclear dotclear 1.2.2

dotclear dotclear 1.2.1

dotclear dotclear 2.5.2

dotclear dotclear 2.5.1

dotclear dotclear 2.2.3

dotclear dotclear 2.2.2

dotclear dotclear 2.1.1

dotclear dotclear 2.1

dotclear dotclear 1.2.6

dotclear dotclear 1.2.5

Exploits

Dotclear versions 262 and below suffer from a remote SQL injection vulnerability ...