Description
Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uploading a file with an executable PHP extension, then accessing it via a direct request to the file in an unspecified directory.
Remediation
References
Related Vulnerabilities
WordPress Plugin Lightbox Jquery Possible Remote Code Execution (0.24)
WordPress Plugin Slideshow Gallery LITE Multiple Vulnerabilities (1.5.3)
WordPress Plugin iframe Cross-Site Scripting (3.0)
WordPress Plugin Mapwiz SQL Injection (1.0.1)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2865)