Description
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.
Remediation
References
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2004-1369)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-2141)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-0763)
WordPress Plugin AdRotate-Ad manager & AdSense Ads 'track' Parameter SQL Injection (3.6.5)
WordPress Plugin WP-Spreadplugin Cross-Site Scripting (3.8.6)