← Back

CVE-2015-8832

nvd nist
Published: Feb 9, 2017Modified: May 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage their own media items" and "manage their own entries and comments" permissions to execute arbitrary PHP code by uploading a file with a (1) .pht, (2) .phps, or (3) .phtml extension.

Affected (1)

Products: Dotclear: Dotclear
1 product
Dotclear
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.8.1

References (16)

Source: security@debian.org
Release NotesVendor Advisory
Source: security@debian.org
ExploitPatchThird Party Advisory
Source: security@debian.org
ExploitMailing ListPatchThird Party Advisory
Source: security@debian.org
Mailing ListPatchThird Party Advisory
Source: security@debian.org
Mailing ListPatchThird Party Advisory
Source: security@debian.org
Source: security@debian.org
ExploitPatchThird Party Advisory
Source: security@debian.org
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory

Timeline

No history available yet.