Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2019-08-22 CVE-2015-9339 Unrestricted Upload of File with Dangerous Type vulnerability in Iptanus Wordpress File Upload
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
network
low complexity
iptanus CWE-434
7.5
2019-08-22 CVE-2015-9338 Unrestricted Upload of File with Dangerous Type vulnerability in Iptanus Wordpress File Upload
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
network
low complexity
iptanus CWE-434
7.5
2019-08-22 CVE-2015-9341 Unrestricted Upload of File with Dangerous Type vulnerability in Iptanus Wordpress File Upload
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
network
low complexity
iptanus CWE-434
7.5
2019-08-22 CVE-2019-11031 Unrestricted Upload of File with Dangerous Type vulnerability in Mirasys VMS 7.6.0/8.0.0/8.3.1
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the auto-update feature of IDVRUpdateService2 in DVRServer.exe.
network
low complexity
mirasys CWE-434
critical
9.8
2019-08-22 CVE-2018-18572 Unrestricted Upload of File with Dangerous Type vulnerability in Oscommerce 2.3.4.1
osCommerce 2.3.4.1 has an incomplete '.htaccess' for blacklist filtering in the "product" page.
network
low complexity
oscommerce CWE-434
7.2
2019-08-16 CVE-2019-15091 Unrestricted Upload of File with Dangerous Type vulnerability in Artica Integria IMS 5.0.86
filemgr.php in Artica Integria IMS 5.0.86 allows index.php?sec=wiki&sec2=operation/wiki/wiki&action=upload arbitrary file upload.
network
low complexity
artica CWE-434
critical
9.8
2019-08-15 CVE-2019-14755 Unrestricted Upload of File with Dangerous Type vulnerability in Leaftecnologia Leaf Admin 61.9.0212.10F
The profile photo upload feature in Leaf Admin 61.9.0212.10 f allows Unrestricted Upload of a File with a Dangerous Type.
network
low complexity
leaftecnologia CWE-434
8.8
2019-08-09 CVE-2019-5395 Unrestricted Upload of File with Dangerous Type vulnerability in HP 3Par Service Processor Firmware
A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.
network
low complexity
hp CWE-434
8.8
2019-08-07 CVE-2019-14748 Unrestricted Upload of File with Dangerous Type vulnerability in Osticket
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1.
network
low complexity
osticket CWE-434
5.4
2019-08-02 CVE-2019-7930 Unrestricted Upload of File with Dangerous Type vulnerability in Magento
A file upload restriction bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2.
network
low complexity
magento CWE-434
7.2