Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9268

Опубликовано: 10 нояб. 2016
Источник: debian
EPSS Низкий

Описание

Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dotclearremovedpackage

Примечания

  • http://dev.dotclear.org/2.0/changeset/445e9ff79a1fa81033591761d6a340e219d159b2

  • http://dev.dotclear.org/2.0/ticket/2214

EPSS

Процентиль: 75%
0.00875
Низкий

Связанные уязвимости

CVSS3: 7.2
nvd
около 9 лет назад

Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.

CVSS3: 7.2
github
больше 3 лет назад

Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.

EPSS

Процентиль: 75%
0.00875
Низкий