← Back

CVE-2014-3783

nvd nist
Published: May 22, 2014Modified: May 6, 2026

JSON object

Loading...
6.0
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:P
Exploitability: 6.8 / Impact: 6.4
Source: NVD

Description

SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission to execute arbitrary SQL commands via the categories_order parameter.

Affected (44)

Products: Dotclear: Dotclear
1 product
Dotclear
Configuration A
44 vulnerable
Vulnerable SoftwareAffected Versions
Dotclear
Up to 2.6.2
Version 1.2.1
Version 1.2.2
Version 1.2.3
Version 1.2.4
Version 1.2.5
Version 1.2.6
Version 1.2.7
Version 1.2.8
Version 2.0.1
Version 2.0.2
Version 2.0
Version 2.0 beta_2
Version 2.0 beta_3
Version 2.0 beta_4
Version 2.0 beta_5.2
Version 2.0 beta_5.4
Version 2.0 beta_6
Version 2.0 beta_7
Version 2.0 rc1
Version 2.0 rc2
Version 2.1.1
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1.6
Version 2.1.7
Version 2.1
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2
Version 2.3.0
Version 2.3.1
Version 2.4.2
Version 2.4.3
Version 2.4.4
Version 2.5.0
Version 2.5.1
Version 2.5.2
Version 2.5.3
Version 2.6.1
Version 2.6
Version 2.6 rc

References (10)

Timeline

No history available yet.