Description
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server CVE-2021-2315 Vulnerability (CVE-2021-2315)
b2evolution Improper Input Validation Vulnerability (CVE-2017-1000423)
SharePoint CVE-2023-29357 Vulnerability (CVE-2023-29357)
Roundcube Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-12626)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2016-5095)