Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some other PHP file extension.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Dotclear | Dotclear | * | 2.6.2 (including) |
Dotclear | Dotclear | 2.6 (including) | 2.6 (including) |
Dotclear | Dotclear | 2.6-rc (including) | 2.6-rc (including) |
Dotclear | Dotclear | 2.6.1 (including) | 2.6.1 (including) |
Dotclear | Ubuntu | precise | * |
Dotclear | Ubuntu | saucy | * |
Dotclear | Ubuntu | trusty | * |
Dotclear | Ubuntu | upstream | * |
Dotclear | Ubuntu | utopic | * |
Dotclear | Ubuntu | vivid | * |
Dotclear | Ubuntu | wily | * |