CVE-2014-1613
NONE EPSS 81.1%
Published May 16, 201412y ago · Modified Jun 17, 20262w ago
Published May 16, 2014 12y ago
Last Modified Jun 17, 2026 2w ago
Description
Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public.php.
Threat Intelligence
EPSS Exploit Probability
81.1% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-94 Improper Control of Generation of Code (Code Injection) Injection
Affected Products 35
| Vendor | Product | Version | Range |
|---|---|---|---|
| dotclear | dotclear | * | ≤2.6.1 |
| dotclear | dotclear | 2.0 | any |
| dotclear | dotclear | 2.0 | any |
| dotclear | dotclear | 2.0 | any |
| dotclear | dotclear | 2.0 | any |
| dotclear | dotclear | 2.0 | any |
| dotclear | dotclear | 2.0 | any |
| dotclear | dotclear | 2.0 | any |
| dotclear | dotclear | 2.0 | any |
| dotclear | dotclear | 2.0 | any |
| dotclear | dotclear | 2.0 | any |
| dotclear | dotclear | 2.0.1 | any |
| dotclear | dotclear | 2.0.2 | any |
| dotclear | dotclear | 2.1 | any |
| dotclear | dotclear | 2.1.1 | any |
| dotclear | dotclear | 2.1.3 | any |
| dotclear | dotclear | 2.1.4 | any |
| dotclear | dotclear | 2.1.5 | any |
| dotclear | dotclear | 2.1.6 | any |
| dotclear | dotclear | 2.1.7 | any |
| dotclear | dotclear | 2.2 | any |
| dotclear | dotclear | 2.2.1 | any |
| dotclear | dotclear | 2.2.2 | any |
| dotclear | dotclear | 2.2.3 | any |
| dotclear | dotclear | 2.3.0 | any |
| dotclear | dotclear | 2.3.1 | any |
| dotclear | dotclear | 2.4.2 | any |
| dotclear | dotclear | 2.4.3 | any |
| dotclear | dotclear | 2.4.4 | any |
| dotclear | dotclear | 2.5.0 | any |
| dotclear | dotclear | 2.5.1 | any |
| dotclear | dotclear | 2.5.2 | any |
| dotclear | dotclear | 2.5.3 | any |
| dotclear | dotclear | 2.6 | any |
| dotclear | dotclear | 2.6 | any |
References 2
- dotclear.org http://dotclear.org/blog/post/2014/01/20/Dotclear-2.6.2
- labs.mwrinfosecurity.com https://labs.mwrinfosecurity.com/advisories/2014/05/14/dotclear-php-object-injection/
Remediation
- dotclear.org http://dotclear.org/blog/post/2014/01/20/Dotclear-2.6.2