Vulnerability Description
Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dotclear | Dotclear | <= 2.6.1 |
Related Weaknesses (CWE)
References
- http://dotclear.org/blog/post/2014/01/20/Dotclear-2.6.2PatchVendor Advisory
- https://labs.mwrinfosecurity.com/advisories/2014/05/14/dotclear-php-object-injecExploit
- http://dotclear.org/blog/post/2014/01/20/Dotclear-2.6.2PatchVendor Advisory
- https://labs.mwrinfosecurity.com/advisories/2014/05/14/dotclear-php-object-injecExploit
FAQ
What is CVE-2014-1613?
CVE-2014-1613 is a vulnerability with a CVSS score of 7.5 (HIGH). Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/publi...
How severe is CVE-2014-1613?
CVE-2014-1613 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-1613?
Check the references section above for vendor advisories and patch information. Affected products include: Dotclear Dotclear.