PT-2014-4258 · Dotclear · Dotclear

Publicado

2014-05-16

·

Atualizado

2014-05-16

·

CVE-2014-1613

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dotclear versions prior to 2.6.2
Description The issue allows remote attackers to execute arbitrary PHP code via a serialized object in the dc passwd cookie to a password-protected page. This is due to improper handling by certain PHP files, including inc/public/lib.urlhandlers.php and plugins/pages/ public.php.
Recommendations For versions prior to 2.6.2, update to version 2.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to password-protected pages or disabling the use of the dc passwd cookie until the update is applied.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-1613

Produtos afetados

Dotclear