Dotclear versions 1.2.7.1 and below suffer from an arbitrary upload vulnerability in ecrire/images.php.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/65529/dotclear-upload.txt
Source: https://packetstormsecurity.com/files/65529/dotclear-upload.txt.html

