CyberSec.Space Logo
CVEブラウザに戻る

CVE-2008-3232

CRITICAL
9.3
CVSS Severity Score
EPSS Score0.0160%
EPSS Percentile41.65th
Published2008年7月18日
Last Modified2026年4月23日

Vulnerability Description

Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images.

Affected Platforms (CPE)

📦
Dotclear

Dotclear

<= 1.2.7
📦
Dotclear

Dotclear

= 1.2.1
📦
Dotclear

Dotclear

= 1.2.2
📦
Dotclear

Dotclear

= 1.2.3
📦
Dotclear

Dotclear

= 1.2.4
📦
Dotclear

Dotclear

= 1.2.5
📦
Dotclear

Dotclear

= 1.2.6

References & Advisories

関連する脆弱性情報