CVE-2014-3781
11.06.2014, 14:55
The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty password in an XML-RPC request.Enginsight
Vendor | Product | Version |
---|---|---|
dotclear | dotclear | 𝑥 ≤ 2.6.2 |
dotclear | dotclear | 2.6 |
dotclear | dotclear | 2.6:rc |
dotclear | dotclear | 2.6.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References