mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 19:17:37 +02:00
797 B
797 B
CVE-2014-3783
Description
SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission to execute arbitrary SQL commands via the categories_order parameter.
POC
Reference
- http://packetstormsecurity.com/files/126768/Dotclear-2.6.2-SQL-Injection.html
- http://packetstormsecurity.com/files/126768/Dotclear-2.6.2-SQL-Injection.html
Github
No PoCs found on GitHub currently.