Description
Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uploading a file with an executable PHP extension, then accessing it via a direct request to the file in an unspecified directory.
Remediation
References
Related Vulnerabilities
WebLogic Missing Authentication for Critical Function Vulnerability (CVE-2024-21007)
WordPress Plugin Content Cards Cross-Site Scripting (0.9.6)
Oracle JRE CVE-2022-21299 Vulnerability (CVE-2022-21299)
PHP Other Vulnerability (CVE-2007-1401)
WordPress Plugin Modula Image Gallery Cross-Site Scripting (2.2.4)