Description
Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage their own media items" and "manage their own entries and comments" permissions to execute arbitrary PHP code by uploading a file with a (1) .pht, (2) .phps, or (3) .phtml extension.
Remediation
References
Related Vulnerabilities
Joomla! Core 1.5.x Multiple Vulnerabilities (1.5.0 - 1.5.3)
Oracle JRE CVE-2013-5832 Vulnerability (CVE-2013-5832)
phpBB Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-5502)
MySQL CVE-2023-21881 Vulnerability (CVE-2023-21881)
Joomla! Core 3.x.x Multiple Cross-Site Scripting Vulnerabilities (3.0.0 - 3.9.3)