İçeriğe atla
Noroxi

dotclear kayıtları

dotclear üreticisine ait 32 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
5
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

32 kayıt
  • CVE-2005-3957
    40Planlayın

    Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.

    KritikCVSS 10,0İstismar yokEPSS %2

    dotclear · dotclear1 Ara 2005

  • CVE-2008-3232
    38İzleyin

    Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arb

    KritikCVSS 9,3İstismar yokEPSS %5

    dotclear · dotclear18 Tem 2008

  • CVE-2016-7902
    36İzleyin

    Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permi

    YüksekCVSS 8,8İstismar yokEPSS %3

    dotclear · dotclear4 Oca 2017

  • CVE-2015-8832
    36İzleyin

    Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "

    YüksekCVSS 8,8İstismar yokEPSS %3

    dotclear · dotclear9 Şub 2017

  • CVE-2023-53952
    34İzleyin

    Dotclear 2.25.3 Authenticated Remote Code Execution via File Upload

    YüksekCVSS 8,7İstismar yokEPSS %1

    dotclear · dotclear19 Ara 2025

  • CVE-2024-58281
    34İzleyin

    Dotclear 2.29 Remote Code Execution via Authenticated File Upload

    YüksekCVSS 8,7İstismar yokEPSS %1

    dotclear · dotclear10 Ara 2025

  • CVE-2011-5083
    31İzleyin

    Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary cod

    YüksekCVSS 7,5İstismar yokEPSS %3

    dotclear · dotclear19 Mar 2012

  • CVE-2014-1613
    31İzleyin

    Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-pr

    YüksekCVSS 7,5İstismar yokEPSS %2

    dotclear · dotclear16 May 2014

  • CVE-2016-9268
    30İzleyin

    Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows

    YüksekCVSS 7,2İstismar yokEPSS %5

    dotclear · dotclear10 Kas 2016

  • CVE-2005-3963
    30İzleyin

    SQL injection vulnerability in session.php in DotClear before 1.2.3 allows remote attackers to execute arbitrary SQL commands via the dc_xd

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    dotclear · dotclear1 Ara 2005

  • CVE-2011-1584
    27İzleyin

    The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, w

    OrtaCVSS 6,5İstismar yokEPSS %2

    dotclear · dotclear8 Haz 2011

  • CVE-2015-8831
    25İzleyin

    Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web scri

    OrtaCVSS 6,1İstismar yokEPSS %2

    dotclear · dotclear9 Şub 2017

  • CVE-2014-3781
    24İzleyin

    The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an

    OrtaCVSS 5,8İstismar yokEPSS %2

    dotclear · dotclear11 Haz 2014

  • CVE-2014-3783
    24İzleyin

    SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories pe

    OrtaCVSS 6,0İstismar yokEPSS %2

    dotclear · dotclear22 May 2014

  • CVE-2016-6523
    24İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary

    OrtaCVSS 6,1İstismar yokEPSS %1

    dotclear · dotclear9 Ara 2016

  • CVE-2014-3782
    24İzleyin

    Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow r

    OrtaCVSS 6,0İstismar yokEPSS %1

    dotclear · dotclear11 Haz 2014

  • CVE-2017-6446
    24İzleyin

    XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.

    OrtaCVSS 6,1İstismar yokEPSS %1

    dotclear · dotclear5 Mar 2017

  • CVE-2024-27626
    24İzleyin

    A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29.

    OrtaCVSS 6,1İstismar yokEPSS %0

    dotclear · dotclear20 Mar 2024

  • CVE-2006-2866
    21İzleyin

    PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP

    OrtaCVSS 5,1Kavram kanıtıEPSS %3

    dotclear · dotclear6 Haz 2006

  • CVE-2006-3938
    21İzleyin

    DotClear allows remote attackers to obtain sensitive information via a direct request for (1) edit_cat.php, (2) index.php, (3) edit_link.php

    OrtaCVSS 5,0İstismar yokEPSS %2

    dotclear · dotclear31 Tem 2006

  • CVE-2016-9891
    21İzleyin

    Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated use

    OrtaCVSS 5,4İstismar yokEPSS %1

    dotclear · dotclear29 Ara 2016

  • CVE-2018-5689
    21İzleyin

    Cross-site scripting (XSS) vulnerability in admin/auth.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scri

    OrtaCVSS 5,4İstismar yokEPSS %1

    dotclear · dotclear14 Oca 2018

  • CVE-2018-5690
    21İzleyin

    Cross-site scripting (XSS) vulnerability in admin/users.php in Dotclear 2.12.1 allows remote authenticated users to inject arbitrary web scr

    OrtaCVSS 5,4İstismar yokEPSS %1

    dotclear · dotclear14 Oca 2018

  • CVE-2018-16358
    21İzleyin

    A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authe

    OrtaCVSS 5,4İstismar yokEPSS %1

    dotclear · dotclear2 Eyl 2018

  • CVE-2012-1039
    18İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML v

    OrtaCVSS 4,3Kavram kanıtıEPSS %4

    dotclear · dotclear19 Mar 2012