Vulnerabilities > Unrestricted Upload of File with Dangerous Type
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-06-29 | CVE-2018-13021 | Unrestricted Upload of File with Dangerous Type vulnerability in Hongcms Project Hongcms 3.0.0 An issue was discovered in HongCMS 3.0.0. | 7.2 |
2018-06-27 | CVE-2018-12914 | Unrestricted Upload of File with Dangerous Type vulnerability in Publiccms 4.0.20180210 A remote code execution issue was discovered in PublicCMS V4.0.20180210. | 9.8 |
2018-06-26 | CVE-2018-1000544 | Unrestricted Upload of File with Dangerous Type vulnerability in multiple products rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. | 9.8 |
2018-06-26 | CVE-2018-0571 | Unrestricted Upload of File with Dangerous Type vulnerability in Basercms baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files. | 4.3 |
2018-06-19 | CVE-2018-12519 | Unrestricted Upload of File with Dangerous Type vulnerability in Codenx Shopnx An issue was discovered in ShopNx through 2017-11-17. | 8.8 |
2018-06-16 | CVE-2018-11221 | Unrestricted Upload of File with Dangerous Type vulnerability in Artica Pandora FMS Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system. | 9.8 |
2018-06-15 | CVE-2018-12491 | Unrestricted Upload of File with Dangerous Type vulnerability in PHPok 4.9.032 PHPOK 4.9.032 has an arbitrary file upload vulnerability in the import_f function in framework/admin/modulec_control.php, as demonstrated by uploading a .php file within a .php.zip archive, a similar issue to CVE-2018-8944. | 9.8 |
2018-06-13 | CVE-2011-4183 | Unrestricted Upload of File with Dangerous Type vulnerability in Opensuse Open Build Service A vulnerability in open build service allows remote attackers to upload arbitrary RPM files. | 9.8 |
2018-06-13 | CVE-2018-12263 | Unrestricted Upload of File with Dangerous Type vulnerability in Portfoliocms Project Portfoliocms 1.0.5 portfolioCMS 1.0.5 allows upload of arbitrary .php files via the admin/portfolio.php?newpage=true URI. | 8.8 |
2018-06-08 | CVE-2018-1453 | Unrestricted Upload of File with Dangerous Type vulnerability in IBM Security Identity Manager 7.0/7.0.1 IBM Security Identity Manager Virtual Appliance 7.0 allows an authenticated attacker to upload or transfer files of dangerous types that can be automatically processed within the environment. | 8.8 |