Vulnerability Database

314,433

Total vulnerabilities in the database

CVE-2011-1584

The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, which allows remote authenticated users to upload and execute arbitrary PHP code via the media_path or media_file parameter. NOTE: some of these details are obtained from third party information.

  • Published: Jun 8, 2011
  • Updated: Nov 9, 2025
  • CVE: CVE-2011-1584
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 6.5
  • AV:N/AC:L/Au:S/C:P/I:P/A:P

CWEs:

Software From Fixed in
dotclear / dotclear 1.2.3 1.2.3.x
dotclear / dotclear 2.0-beta_7 2.0-beta_7.x
dotclear / dotclear - 2.2.2.x
dotclear / dotclear 2.0-beta_5.4 2.0-beta_5.4.x
dotclear / dotclear 2.2.1 2.2.1.x
dotclear / dotclear 2.0-beta_5.2 2.0-beta_5.2.x
dotclear / dotclear 2.1 2.1.x
dotclear / dotclear 2.0.1 2.0.1.x
dotclear / dotclear 2.0.2 2.0.2.x
dotclear / dotclear 2.1.4 2.1.4.x
dotclear / dotclear 2.0 2.0.x
dotclear / dotclear 1.2.5 1.2.5.x
dotclear / dotclear 2.0-beta_3 2.0-beta_3.x
dotclear / dotclear 2.1.1 2.1.1.x
dotclear / dotclear 1.2.2 1.2.2.x
dotclear / dotclear 2.0-beta_4 2.0-beta_4.x
dotclear / dotclear 2.0-rc1 2.0-rc1.x
dotclear / dotclear 1.2.6 1.2.6.x
dotclear / dotclear 2.1.5 2.1.5.x
dotclear / dotclear 2.1.7 2.1.7.x
dotclear / dotclear 2.0-beta_2 2.0-beta_2.x
dotclear / dotclear 2.0-beta_6 2.0-beta_6.x
dotclear / dotclear 1.2.7 1.2.7.x
dotclear / dotclear 2.0-rc2 2.0-rc2.x
dotclear / dotclear 2.2 2.2.x
dotclear / dotclear 1.2.4 1.2.4.x
dotclear / dotclear 2.1.6 2.1.6.x
dotclear / dotclear 2.1.3 2.1.3.x
dotclear / dotclear 1.2.1 1.2.1.x
dotclear / dotclear 1.2.8 1.2.8.x