9.3
CVSSv2

CVE-2008-3232

Published: 18/07/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and previous versions allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images.

Vulnerable Product Search on Vulmon Subscribe to Product

dotclear dotclear 1.2.2

dotclear dotclear 1.2.3

dotclear dotclear 1.2.6

dotclear dotclear

dotclear dotclear 1.2.1

dotclear dotclear 1.2.4

dotclear dotclear 1.2.5