Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-556x-hp2x-vvgc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public.php.

Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public.php.

EPSS

Процентиль: 68%
0.0058
Низкий

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 11 лет назад

Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public.php.

nvd
больше 11 лет назад

Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public.php.

debian
больше 11 лет назад

Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP ...

EPSS

Процентиль: 68%
0.0058
Низкий

Дефекты

CWE-94