Vulnerabilities > Unrestricted Upload of File with Dangerous Type
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-08-13 | CVE-2018-15139 | Unrestricted Upload of File with Dangerous Type vulnerability in Open-Emr Openemr Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and accessing it in the images directory. | 8.8 |
2018-08-10 | CVE-2018-14028 | Unrestricted Upload of File with Dangerous Type vulnerability in Wordpress 4.9.7 In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. | 7.2 |
2018-08-08 | CVE-2018-15137 | Unrestricted Upload of File with Dangerous Type vulnerability in Cela Link Clr-M20 Firmware 2.7.1.6 CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. | 9.8 |
2018-08-06 | CVE-2018-14857 | Unrestricted Upload of File with Dangerous Type vulnerability in Ocsinventory-Ng OCS Inventory Server Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template file containing PHP code, because file extensions other than .html are permitted. | 8.8 |
2018-08-03 | CVE-2018-14911 | Unrestricted Upload of File with Dangerous Type vulnerability in Ukcms A file upload vulnerability exists in ukcms v1.1.7 and earlier. | 7.2 |
2018-08-01 | CVE-2018-12468 | Unrestricted Upload of File with Dangerous Type vulnerability in Microfocus Groupwise 18/18.0.1 A vulnerability in the administration console of Micro Focus GroupWise prior to version 18.0.2 may allow a remote attacker authenticated as an administrator to upload files to an arbitrary path on the server. | 7.2 |
2018-07-31 | CVE-2018-12940 | Unrestricted Upload of File with Dangerous Type vulnerability in Seeddms Unrestricted file upload vulnerability in "op/op.UploadChunks.php" in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension specified by the "qqfile" parameter. | 8.8 |
2018-07-24 | CVE-2017-3189 | Unrestricted Upload of File with Dangerous Type vulnerability in Dotcms The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. | 8.1 |
2018-07-23 | CVE-2018-14570 | Unrestricted Upload of File with Dangerous Type vulnerability in Niushop B2B2C Multi-Business 1.11 A file upload vulnerability in application/shop/controller/member.php in Niushop B2B2C Multi-business basic version V1.11 allows any remote member to upload a .php file to the web server via a profile avatar field, by using an image Content-Type (e.g., image/jpeg) with a modified filename and file content. | 8.8 |
2018-07-20 | CVE-2018-14441 | Unrestricted Upload of File with Dangerous Type vulnerability in SSH Companywebsite Project SSH Companywebsite 20180503 An issue was discovered in cckevincyh SSH CompanyWebsite through 2018-05-03. | 9.8 |