Dotclear CVE-2014-3781 Authentication Bypass Vulnerability
BID:67560
Info
Dotclear CVE-2014-3781 Authentication Bypass Vulnerability
| Bugtraq ID: | 67560 |
| Class: | Design Error |
| CVE: |
CVE-2014-3781 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2014 12:00AM |
| Updated: | May 22 2014 12:00AM |
| Credit: | Egidio Romano of karmainsecurity. |
| Vulnerable: |
Dotclear Dotclear 2.6.2 |
| Not Vulnerable: |
Dotclear Dotclear 2.6.3 |
Discussion
Dotclear CVE-2014-3781 Authentication Bypass Vulnerability
Dotclear is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
Dotclear 2.6.2 and prior are vulnerable.
Dotclear is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may aid in further attacks.
Dotclear 2.6.2 and prior are vulnerable.
Exploit / POC
Dotclear CVE-2014-3781 Authentication Bypass Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
Dotclear CVE-2014-3781 Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Dotclear CVE-2014-3781 Authentication Bypass Vulnerability
References:
References:
- Dotclear 2.6.3 Release Notes (Dotclear)
- Dotclear Authentication Bypass Vulnerability (Dotclear)
- Dotclear Homepage (Dotclear)