Description
Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uploading a file with an executable PHP extension, then accessing it via a direct request to the file in an unspecified directory.
Remediation
References
Related Vulnerabilities
WordPress 4.0.x Possible SQL Injection Vulnerability (4.0 - 4.0.19)
MySQL CVE-2013-5881 Vulnerability (CVE-2013-5881)
WordPress Plugin All-in-One Addons for Elementor-WidgetKit Cross-Site Scripting (2.4.3)
WordPress Plugin Welcart e-Commerce Multiple Vulnerabilities (1.4.17)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-5338)