CVE-2016-9268

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
10/11/2016
Last modified:
12/04/2025

Description

Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dotclear:dotclear:*:*:*:*:*:*:*:* 2.10.4 (including)