Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2018-08-13 CVE-2018-15139 Unrestricted Upload of File with Dangerous Type vulnerability in Open-Emr Openemr
Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and accessing it in the images directory.
network
low complexity
open-emr CWE-434
8.8
2018-08-10 CVE-2018-14028 Unrestricted Upload of File with Dangerous Type vulnerability in Wordpress 4.9.7
In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files.
network
low complexity
wordpress CWE-434
7.2
2018-08-08 CVE-2018-15137 Unrestricted Upload of File with Dangerous Type vulnerability in Cela Link Clr-M20 Firmware 2.7.1.6
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well.
network
low complexity
cela-link CWE-434
critical
9.8
2018-08-06 CVE-2018-14857 Unrestricted Upload of File with Dangerous Type vulnerability in Ocsinventory-Ng OCS Inventory Server
Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template file containing PHP code, because file extensions other than .html are permitted.
network
low complexity
ocsinventory-ng CWE-434
8.8
2018-08-03 CVE-2018-14911 Unrestricted Upload of File with Dangerous Type vulnerability in Ukcms
A file upload vulnerability exists in ukcms v1.1.7 and earlier.
network
low complexity
ukcms CWE-434
7.2
2018-08-01 CVE-2018-12468 Unrestricted Upload of File with Dangerous Type vulnerability in Microfocus Groupwise 18/18.0.1
A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an administrator to upload files to an arbitrary path on the server.
network
low complexity
microfocus CWE-434
7.2
2018-07-31 CVE-2018-12940 Unrestricted Upload of File with Dangerous Type vulnerability in Seeddms
Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension specified by the "qqfile" parameter.
network
low complexity
seeddms CWE-434
8.8
2018-07-24 CVE-2017-3189 Unrestricted Upload of File with Dangerous Type vulnerability in Dotcms
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload.
network
high complexity
dotcms CWE-434
8.1
2018-07-23 CVE-2018-14570 Unrestricted Upload of File with Dangerous Type vulnerability in Niushop B2B2C Multi-Business 1.11
A file upload vulnerability in application/shop/controller/member.php in Niushop B2B2C Multi-business basic version V1.11 allows any remote member to upload a .php file to the web server via a profile avatar field, by using an image Content-Type (e.g., image/jpeg) with a modified filename and file content.
network
low complexity
niushop CWE-434
8.8
2018-07-20 CVE-2018-14441 Unrestricted Upload of File with Dangerous Type vulnerability in SSH Companywebsite Project SSH Companywebsite 20180503
An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03.
network
low complexity
ssh-companywebsite-project CWE-434
critical
9.8