Description
Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some other PHP file extension.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Visitor Statistics (Real Time Traffic) SQL Injection (5.7)
WordPress Plugin Lazy content Slider Cross-Site Request Forgery (3.4)
WordPress Plugin Easy Digital Downloads Attach Accounts to Orders Cross-Site Scripting (2.0.1)
WordPress 5.6.x Prototype Pollution (5.6 - 5.6.7)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-0059)