Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some other PHP file extension. Per: http://cwe.mitre.org/data/definitions/184.html
"CWE-184: Incomplete Blacklist"
Publication date: Wed, 11 Jun 2014 19:55:00 +0000