dotclear kayıtları
dotclear üreticisine ait 32 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-287 Improper Authentication1
- CWE-284 Improper Access Control1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
32 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2005-3957İstismar yok | Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.dotclear · dotclear | Kritik10,0 | — | %1,6 | 1 Ara 2005 |
38İzleyin | CVE-2008-3232İstismar yok | Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbdotclear · dotclear · CWE-94 | Kritik9,3 | — | %4,6 | 18 Tem 2008 |
36İzleyin | CVE-2016-7902İstismar yok | Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permidotclear · dotclear · CWE-434 | Yüksek8,8 | — | %3,0 | 4 Oca 2017 |
36İzleyin | CVE-2015-8832İstismar yok | Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "dotclear · dotclear · CWE-284 | Yüksek8,8 | — | %2,6 | 9 Şub 2017 |
34İzleyin | CVE-2023-53952İstismar yok | Dotclear 2.25.3 Authenticated Remote Code Execution via File Uploaddotclear · dotclear · CWE-434 | Yüksek8,7 | — | %1,1 | 19 Ara 2025 |
34İzleyin | CVE-2024-58281İstismar yok | Dotclear 2.29 Remote Code Execution via Authenticated File Uploaddotclear · dotclear · CWE-434 | Yüksek8,7 | — | %0,9 | 10 Ara 2025 |
31İzleyin | CVE-2011-5083İstismar yok | Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary coddotclear · dotclear · CWE-264 | Yüksek7,5 | — | %3,3 | 19 Mar 2012 |
31İzleyin | CVE-2014-1613İstismar yok | Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-prdotclear · dotclear · CWE-94 | Yüksek7,5 | — | %2,3 | 16 May 2014 |
30İzleyin | CVE-2016-9268İstismar yok | Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows dotclear · dotclear · CWE-434 | Yüksek7,2 | — | %5,0 | 10 Kas 2016 |
30İzleyin | CVE-2005-3963Kavram kanıtı | SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd dotclear · dotclear | Yüksek7,5 | — | %1,4 | 1 Ara 2005 |
27İzleyin | CVE-2011-1584İstismar yok | The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, wdotclear · dotclear · CWE-264 | Orta6,5 | — | %1,7 | 8 Haz 2011 |
25İzleyin | CVE-2015-8831İstismar yok | Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web scridotclear · dotclear · CWE-79 | Orta6,1 | — | %2,1 | 9 Şub 2017 |
24İzleyin | CVE-2014-3781İstismar yok | The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via andotclear · dotclear · CWE-287 | Orta5,8 | — | %2,2 | 11 Haz 2014 |
24İzleyin | CVE-2014-3783İstismar yok | SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories pedotclear · dotclear · CWE-89 | Orta6,0 | — | %1,7 | 22 May 2014 |
24İzleyin | CVE-2016-6523İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary dotclear · dotclear · CWE-79 | Orta6,1 | — | %1,3 | 9 Ara 2016 |
24İzleyin | CVE-2014-3782İstismar yok | Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow rdotclear · dotclear | Orta6,0 | — | %1,2 | 11 Haz 2014 |
24İzleyin | CVE-2017-6446İstismar yok | XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.dotclear · dotclear · CWE-79 | Orta6,1 | — | %0,7 | 5 Mar 2017 |
24İzleyin | CVE-2024-27626İstismar yok | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29.dotclear · dotclear · CWE-79 | Orta6,1 | — | %0,4 | 20 Mar 2024 |
21İzleyin | CVE-2006-2866Kavram kanıtı | PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHPdotclear · dotclear | Orta5,1 | — | %3,2 | 6 Haz 2006 |
21İzleyin | CVE-2006-3938İstismar yok | DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.phpdotclear · dotclear | Orta5,0 | — | %2,3 | 31 Tem 2006 |
21İzleyin | CVE-2016-9891İstismar yok | Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated usedotclear · dotclear · CWE-79 | Orta5,4 | — | %1,0 | 29 Ara 2016 |
21İzleyin | CVE-2018-5689İstismar yok | Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scridotclear · dotclear · CWE-79 | Orta5,4 | — | %0,9 | 14 Oca 2018 |
21İzleyin | CVE-2018-5690İstismar yok | Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scrdotclear · dotclear · CWE-79 | Orta5,4 | — | %0,9 | 14 Oca 2018 |
21İzleyin | CVE-2018-16358İstismar yok | A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authedotclear · dotclear · CWE-79 | Orta5,4 | — | %0,7 | 2 Eyl 2018 |
18İzleyin | CVE-2012-1039Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML vdotclear · dotclear · CWE-79 | Orta4,3 | — | %4,0 | 19 Mar 2012 |
- CVE-2005-395740Planlayın
Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.
KritikCVSS 10,0İstismar yokEPSS %2dotclear · dotclear1 Ara 2005
- CVE-2008-323238İzleyin
Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arb
KritikCVSS 9,3İstismar yokEPSS %5dotclear · dotclear18 Tem 2008
- CVE-2016-790236İzleyin
Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permi
YüksekCVSS 8,8İstismar yokEPSS %3dotclear · dotclear4 Oca 2017
- CVE-2015-883236İzleyin
Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "
YüksekCVSS 8,8İstismar yokEPSS %3dotclear · dotclear9 Şub 2017
- CVE-2023-5395234İzleyin
Dotclear 2.25.3 Authenticated Remote Code Execution via File Upload
YüksekCVSS 8,7İstismar yokEPSS %1dotclear · dotclear19 Ara 2025
- CVE-2024-5828134İzleyin
Dotclear 2.29 Remote Code Execution via Authenticated File Upload
YüksekCVSS 8,7İstismar yokEPSS %1dotclear · dotclear10 Ara 2025
- CVE-2011-508331İzleyin
Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary cod
YüksekCVSS 7,5İstismar yokEPSS %3dotclear · dotclear19 Mar 2012
- CVE-2014-161331İzleyin
Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-pr
YüksekCVSS 7,5İstismar yokEPSS %2dotclear · dotclear16 May 2014
- CVE-2016-926830İzleyin
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows
YüksekCVSS 7,2İstismar yokEPSS %5dotclear · dotclear10 Kas 2016
- CVE-2005-396330İzleyin
SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd
YüksekCVSS 7,5Kavram kanıtıEPSS %1dotclear · dotclear1 Ara 2005
- CVE-2011-158427İzleyin
The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, w
OrtaCVSS 6,5İstismar yokEPSS %2dotclear · dotclear8 Haz 2011
- CVE-2015-883125İzleyin
Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web scri
OrtaCVSS 6,1İstismar yokEPSS %2dotclear · dotclear9 Şub 2017
- CVE-2014-378124İzleyin
The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an
OrtaCVSS 5,8İstismar yokEPSS %2dotclear · dotclear11 Haz 2014
- CVE-2014-378324İzleyin
SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories pe
OrtaCVSS 6,0İstismar yokEPSS %2dotclear · dotclear22 May 2014
- CVE-2016-652324İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary
OrtaCVSS 6,1İstismar yokEPSS %1dotclear · dotclear9 Ara 2016
- CVE-2014-378224İzleyin
Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow r
OrtaCVSS 6,0İstismar yokEPSS %1dotclear · dotclear11 Haz 2014
- CVE-2017-644624İzleyin
XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.
OrtaCVSS 6,1İstismar yokEPSS %1dotclear · dotclear5 Mar 2017
- CVE-2024-2762624İzleyin
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29.
OrtaCVSS 6,1İstismar yokEPSS %0dotclear · dotclear20 Mar 2024
- CVE-2006-286621İzleyin
PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP
OrtaCVSS 5,1Kavram kanıtıEPSS %3dotclear · dotclear6 Haz 2006
- CVE-2006-393821İzleyin
DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php
OrtaCVSS 5,0İstismar yokEPSS %2dotclear · dotclear31 Tem 2006
- CVE-2016-989121İzleyin
Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated use
OrtaCVSS 5,4İstismar yokEPSS %1dotclear · dotclear29 Ara 2016
- CVE-2018-568921İzleyin
Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scri
OrtaCVSS 5,4İstismar yokEPSS %1dotclear · dotclear14 Oca 2018
- CVE-2018-569021İzleyin
Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scr
OrtaCVSS 5,4İstismar yokEPSS %1dotclear · dotclear14 Oca 2018
- CVE-2018-1635821İzleyin
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authe
OrtaCVSS 5,4İstismar yokEPSS %1dotclear · dotclear2 Eyl 2018
- CVE-2012-103918İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML v
OrtaCVSS 4,3Kavram kanıtıEPSS %4dotclear · dotclear19 Mar 2012