High severity7.2NVD Advisory· Published Nov 10, 2016· Updated May 6, 2026
CVE-2016-9268
CVE-2016-9268
Description
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- dev.dotclear.org/2.0/changeset/445e9ff79a1fa81033591761d6a340e219d159b2nvdIssue TrackingPatch
- dev.dotclear.org/2.0/ticket/2214nvdMitigationVendor Advisory
- www.securityfocus.com/bid/94246nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.