Description
Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uploading a file with an executable PHP extension, then accessing it via a direct request to the file in an unspecified directory.
Remediation
References
Related Vulnerabilities
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-20920)
WordPress Plugin WordPress Button Plugin MaxButtons Cross-Site Scripting (1.26.0)
phpMyFAQ Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-0788)
WebLogic CVE-2018-2625 Vulnerability (CVE-2018-2625)
WordPress Plugin Auto Amazon Links-Amazon Associates Affiliate Unspecified Vulnerability (2.0.3.4)