CVE-2015-8832

CVE-2015-8832

Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage their own media items" and "manage their own entries and comments" permissions to execute arbitrary PHP code by uploading a file with a (1) .pht, (2) .phps, or (3) .phtml extension.

Source: CVE-2015-8832

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다