CVE-2016-7902
- EPSS 2.36%
- Veröffentlicht 04.01.2017 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file with a crafte...
CVE-2016-9891
- EPSS 0.36%
- Veröffentlicht 29.12.2016 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated users to inject arbitrary web script or HTML via the upfiletitle or media_title parameter (aka the media title).
CVE-2016-6523
- EPSS 0.79%
- Veröffentlicht 09.12.2016 20:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter to admin/media.php.
- EPSS 0.88%
- Veröffentlicht 10.11.2016 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip exte...
CVE-2015-5651
- EPSS 0.32%
- Veröffentlicht 03.10.2015 22:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Dotclear before 2.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2014-5316
- EPSS 0.31%
- Veröffentlicht 22.09.2014 01:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Dotclear before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted page.
- EPSS 0.83%
- Veröffentlicht 11.06.2014 14:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2)...
CVE-2014-3781
- EPSS 0.45%
- Veröffentlicht 11.06.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty password in an XML-RPC request.
- EPSS 0.33%
- Veröffentlicht 22.05.2014 15:13:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission to execute arbitrary SQL commands via the categories_order parameter.
CVE-2014-1613
- EPSS 0.58%
- Veröffentlicht 16.05.2014 15:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public...