Input validation error in Dotclear - CVE-2014-3782
Published: June 11, 2014 / Updated: August 10, 2020
Dotclear
Detailed vulnerability description
The vulnerability allows a remote #AU# to read and manipulate data.
Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some other PHP file extension. Per: http://cwe.mitre.org/data/definitions/184.html "CWE-184: Incomplete Blacklist"