Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2018-05-15 CVE-2018-11098 Unrestricted Upload of File with Dangerous Type vulnerability in Frog CMS Project Frog CMS 0.9.5
An issue was discovered in Frog CMS 0.9.5.
network
low complexity
frog-cms-project CWE-434
7.2
2018-05-14 CVE-2018-11091 Unrestricted Upload of File with Dangerous Type vulnerability in Mybiz Myprocurenet 5.0.0
An issue was discovered in MyBiz MyProcureNet 5.0.0.
network
low complexity
mybiz CWE-434
critical
9.9
2018-05-14 CVE-2018-0587 Unrestricted Upload of File with Dangerous Type vulnerability in Ultimatemember User Profile & Membership
Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.
network
low complexity
ultimatemember CWE-434
4.3
2018-05-14 CVE-2018-0568 Unrestricted Upload of File with Dangerous Type vulnerability in Sitebridge Joruri GW
Unrestricted file upload vulnerability in SiteBridge Inc.
network
low complexity
sitebridge CWE-434
8.8
2018-05-10 CVE-2018-10942 Unrestricted Upload of File with Dangerous Type vulnerability in Attribute Wizard Project Attribute Wizard 1.6.9
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.
network
low complexity
attribute-wizard-project CWE-434
critical
9.8
2018-05-09 CVE-2018-2420 Unrestricted Upload of File with Dangerous Type vulnerability in SAP Internet Graphics Server
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.
network
low complexity
sap CWE-434
critical
9.8
2018-05-07 CVE-2018-10795 Unrestricted Upload of File with Dangerous Type vulnerability in Liferay Portal
Liferay 6.2.x and before has an FCKeditor configuration that allows an attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment via a browser/liferay/browser.html?Type= or html/js/editor/fckeditor/editor/filemanager/browser/liferay/browser.html URI.
network
low complexity
liferay CWE-434
8.8
2018-05-02 CVE-2018-0258 Unrestricted Upload of File with Dangerous Type vulnerability in Cisco products
A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files.
network
low complexity
cisco CWE-434
critical
9.8
2018-05-02 CVE-2018-10577 Unrestricted Upload of File with Dangerous Type vulnerability in Watchguard products
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.
network
low complexity
watchguard CWE-434
8.8
2018-05-01 CVE-2016-10036 Unrestricted Upload of File with Dangerous Type vulnerability in Jfrog Artifactory
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.
network
low complexity
jfrog CWE-434
critical
9.8