Looking for the vulnerability index of Invicti's legacy products?
Dotclear Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-9268) - Vulnerability Database

Dotclear Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-9268)

Description

Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.

References