Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2020-01-23 CVE-2019-16514 Unrestricted Upload of File with Dangerous Type vulnerability in Connectwise Control 19.3.25270.7185
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
network
low complexity
connectwise CWE-434
7.2
2020-01-23 CVE-2013-6358 Unrestricted Upload of File with Dangerous Type vulnerability in Prestashop 1.5.5.0
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
network
low complexity
prestashop CWE-434
8.8
2020-01-21 CVE-2012-5190 Unrestricted Upload of File with Dangerous Type vulnerability in Accusoft Prizm Content Connect 5.1
Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability
network
low complexity
accusoft CWE-434
critical
9.8
2020-01-21 CVE-2020-7246 Unrestricted Upload of File with Dangerous Type vulnerability in Qdpm 8.3/9.0/9.1
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier.
network
low complexity
qdpm CWE-434
8.8
2020-01-21 CVE-2019-20385 Unrestricted Upload of File with Dangerous Type vulnerability in Logaritmo Aware Callmanager 2012
The CSV upload feature in /supervisor/procesa_carga.php on Logaritmo Aware CallManager 2012 devices allows upload of .php files with a text/* content type.
network
low complexity
logaritmo CWE-434
8.8
2020-01-15 CVE-2020-2730 Unrestricted Upload of File with Dangerous Type vulnerability in Oracle Revenue Management and Billing 2.7.0.0/2.7.0.1/2.8.0.0
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: File Upload).
network
low complexity
oracle CWE-434
5.4
2020-01-15 CVE-2011-4907 Unrestricted Upload of File with Dangerous Type vulnerability in Joomla Joomla!
Joomla! 1.5x through 1.5.12: Missing JEXEC Check
network
low complexity
joomla CWE-434
5.3
2020-01-14 CVE-2011-2933 Unrestricted Upload of File with Dangerous Type vulnerability in Websitebaker
An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5, and .phtl extensions.
network
low complexity
websitebaker CWE-434
7.2
2020-01-14 CVE-2020-5509 Unrestricted Upload of File with Dangerous Type vulnerability in PHPgurukul CAR Rental Portal 1.0
PHPGurukul Car Rental Project v1.0 allows Remote Code Execution via an executable file in an upload of a new profile image.
network
low complexity
phpgurukul CWE-434
7.2
2020-01-09 CVE-2019-20183 Unrestricted Upload of File with Dangerous Type vulnerability in Employee Records System Project Employee Records System 1.0
uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the client side.
network
low complexity
employee-records-system-project CWE-434
7.2