Unrated severityNVD Advisory· Published Jun 8, 2011· Updated Apr 29, 2026
CVE-2011-1584
CVE-2011-1584
Description
The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, which allows remote authenticated users to upload and execute arbitrary PHP code via the media_path or media_file parameter. NOTE: some of these details are obtained from third party information.
Affected products
30cpe:2.3:a:dotclear:dotclear:*:*:*:*:*:*:*:*+ 29 more
- cpe:2.3:a:dotclear:dotclear:*:*:*:*:*:*:*:*range: <=2.2.2
- cpe:2.3:a:dotclear:dotclear:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:1.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:1.2.3:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:1.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:1.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:1.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:1.2.7:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:1.2.8:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.0:beta_2:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.0:beta_3:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.0:beta_4:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.0:beta_5.2:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.0:beta_5.4:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.0:beta_6:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.0:beta_7:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.1.4:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.1.5:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.1.6:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.1.7:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.2:*:*:*:*:*:*:*
- cpe:2.3:a:dotclear:dotclear:2.2.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- dotclear.org/blog/post/2011/04/01/Dotclear-2.2.3nvdPatchVendor Advisory
- dev.dotclear.org/2.0/changeset/2:3427nvdExploitPatch
- fr.dotclear.org/blog/post/2011/04/01/Dotclear-2.2.3nvdVendor Advisory
- secunia.com/advisories/44049nvdVendor Advisory
- openwall.com/lists/oss-security/2011/04/13/19nvd
- openwall.com/lists/oss-security/2011/04/14/8nvd
- openwall.com/lists/oss-security/2011/04/15/11nvd
- openwall.com/lists/oss-security/2011/04/15/7nvd
- www.arcabit.com/english/home/a-flaw-in-dotclearnvd
News mentions
0No linked articles in our index yet.