← Back

CVE-2014-1613

nvd nist
Published: May 16, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public.php.

Affected (35)

Products: Dotclear: Dotclear
1 product
Dotclear
Configuration A
35 vulnerable
Vulnerable SoftwareAffected Versions
Dotclear
Up to 2.6.1
Version 2.0.1
Version 2.0.2
Version 2.0
Version 2.0 beta_2
Version 2.0 beta_3
Version 2.0 beta_4
Version 2.0 beta_5.2
Version 2.0 beta_5.4
Version 2.0 beta_6
Version 2.0 beta_7
Version 2.0 rc1
Version 2.0 rc2
Version 2.1.1
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1.6
Version 2.1.7
Version 2.1
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2
Version 2.3.0
Version 2.3.1
Version 2.4.2
Version 2.4.3
Version 2.4.4
Version 2.5.0
Version 2.5.1
Version 2.5.2
Version 2.5.3
Version 2.6
Version 2.6 rc

References (4)

Timeline

No history available yet.