Dotclear Media Manager Arbitrary File Upload Vulnerability
BID:47358
Info
Dotclear Media Manager Arbitrary File Upload Vulnerability
| Bugtraq ID: | 47358 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 13 2011 12:00AM |
| Updated: | Apr 15 2011 07:24AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Dotclear Dotclear 2.2.2 |
| Not Vulnerable: |
Dotclear Dotclear 2.2.3 |
Discussion
Dotclear Media Manager Arbitrary File Upload Vulnerability
Dotclear is prone to an arbitrary-file-upload vulnerability.
An attacker can exploit this issue to upload arbitrary code and run it in the context of the webserver process.
Versions prior to Dotclear 2.2.3 are vulnerable.
Dotclear is prone to an arbitrary-file-upload vulnerability.
An attacker can exploit this issue to upload arbitrary code and run it in the context of the webserver process.
Versions prior to Dotclear 2.2.3 are vulnerable.
Exploit / POC
Dotclear Media Manager Arbitrary File Upload Vulnerability
Attackers can exploit this issue using a browser.
Attackers can exploit this issue using a browser.
Solution / Fix
Dotclear Media Manager Arbitrary File Upload Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Dotclear Media Manager Arbitrary File Upload Vulnerability
References:
References:
- Dotclear 2.2.3 (Dotclear)
- Dotclear Homepage (Dotclear)