Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2021-06-02 CVE-2020-35442 Unrestricted Upload of File with Dangerous Type vulnerability in Fangfa Fdcms 4.0
FDCMS (also known as Fangfa Content Management System) 4.0 allows remote attackers to get a webshell in the background via Front/lib/Action/FindexAction.class.php.
network
low complexity
fangfa CWE-434
critical
9.8
2021-05-29 CVE-2021-31703 Unrestricted Upload of File with Dangerous Type vulnerability in Frontiersoftware Ichris 5.18
Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by any client user.
network
low complexity
frontiersoftware CWE-434
critical
9.8
2021-05-26 CVE-2020-26678 Unrestricted Upload of File with Dangerous Type vulnerability in Vfairs 3.3
vFairs 3.3 is affected by Remote Code Execution.
network
low complexity
vfairs CWE-434
8.8
2021-05-21 CVE-2020-23765 Unrestricted Upload of File with Dangerous Type vulnerability in Bludit 3.12.0
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0.
network
low complexity
bludit CWE-434
7.2
2021-05-20 CVE-2021-20721 Unrestricted Upload of File with Dangerous Type vulnerability in Kujirahand Konawiki
KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors.
network
low complexity
kujirahand CWE-434
critical
9.8
2021-05-17 CVE-2021-32622 Unrestricted Upload of File with Dangerous Type vulnerability in Matrix-React-Sdk Project Matrix-React-Sdk
Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page.
local
low complexity
matrix-react-sdk-project CWE-434
7.8
2021-05-14 CVE-2020-18166 Unrestricted Upload of File with Dangerous Type vulnerability in Laobancms 2.0
Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj=../templets/pc".
network
low complexity
laobancms CWE-434
critical
9.8
2021-05-13 CVE-2020-20092 Unrestricted Upload of File with Dangerous Type vulnerability in Articlecms Project Articlecms 1.0
File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code.
network
low complexity
articlecms-project CWE-434
critical
9.8
2021-05-13 CVE-2020-28063 Unrestricted Upload of File with Dangerous Type vulnerability in Articlecms Project Articlecms
A file upload issue exists in all versions of ArticleCMS which allows malicious users to getshell.
network
low complexity
articlecms-project CWE-434
critical
9.8
2021-05-12 CVE-2020-23790 Unrestricted Upload of File with Dangerous Type vulnerability in Uxper Golo 1.1.5
An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5.
network
low complexity
uxper CWE-434
critical
9.8