Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 10 min 100 bronnen 3 kritiek 8 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2016-7902

HIGH · 8.8 CVSS Gepubliceerd: CWE-434

Beschrijving

Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file with a crafted extension, as demonstrated by .php.txt or .php%20.

Vendors

Dotclear

Affected products

Dotclear

References