Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2018-06-29 CVE-2018-13021 Unrestricted Upload of File with Dangerous Type vulnerability in Hongcms Project Hongcms 3.0.0
An issue was discovered in HongCMS 3.0.0.
network
low complexity
hongcms-project CWE-434
7.2
2018-06-27 CVE-2018-12914 Unrestricted Upload of File with Dangerous Type vulnerability in Publiccms 4.0.20180210
A remote code execution issue was discovered in PublicCMS V4.0.20180210.
network
low complexity
publiccms CWE-434
critical
9.8
2018-06-26 CVE-2018-1000544 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem.
network
low complexity
rubyzip-project debian redhat CWE-434
critical
9.8
2018-06-26 CVE-2018-0571 Unrestricted Upload of File with Dangerous Type vulnerability in Basercms
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files.
network
low complexity
basercms CWE-434
4.3
2018-06-19 CVE-2018-12519 Unrestricted Upload of File with Dangerous Type vulnerability in Codenx Shopnx
An issue was discovered in ShopNx through 2017-11-17.
network
low complexity
codenx CWE-434
8.8
2018-06-16 CVE-2018-11221 Unrestricted Upload of File with Dangerous Type vulnerability in Artica Pandora FMS
Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.
network
low complexity
artica CWE-434
critical
9.8
2018-06-15 CVE-2018-12491 Unrestricted Upload of File with Dangerous Type vulnerability in PHPok 4.9.032
PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar issue to CVE-2018-8944.
network
low complexity
phpok CWE-434
critical
9.8
2018-06-13 CVE-2011-4183 Unrestricted Upload of File with Dangerous Type vulnerability in Opensuse Open Build Service
A vulnerability in open build service allows remote attackers to upload arbitrary RPM files.
network
low complexity
opensuse CWE-434
critical
9.8
2018-06-13 CVE-2018-12263 Unrestricted Upload of File with Dangerous Type vulnerability in Portfoliocms Project Portfoliocms 1.0.5
portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI.
network
low complexity
portfoliocms-project CWE-434
8.8
2018-06-08 CVE-2018-1453 Unrestricted Upload of File with Dangerous Type vulnerability in IBM Security Identity Manager 7.0/7.0.1
IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be automatically processed within the environment.
network
low complexity
ibm CWE-434
8.8