Vulnerabilities > CVE-2014-3782 - Unspecified vulnerability in Dotclear

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some other PHP file extension.

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/126767/KIS-2014-06.txt
idPACKETSTORM:126767
last seen2016-12-05
published2014-05-22
reporterEgiX
sourcehttps://packetstormsecurity.com/files/126767/Dotclear-2.6.2-Arbitrary-File-Upload.html
titleDotclear 2.6.2 Arbitrary File Upload