6
CVSSv2

CVE-2014-3782

Published: 11/06/2014 Updated: 12/06/2014
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear prior to 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some other PHP file extension.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dotclear dotclear 2.6.1

dotclear dotclear 2.6

dotclear dotclear

Exploits

Dotclear versions 262 and below suffer from a remote shell upload vulnerability ...