Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2017-10-04 CVE-2017-12617 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
network
high complexity
apache canonical oracle debian netapp redhat CWE-434
8.1
2017-10-03 CVE-2017-6090 Unrestricted Upload of File with Dangerous Type vulnerability in PHPcollab 2.5/2.5.1
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.
network
low complexity
phpcollab CWE-434
6.5
2017-10-02 CVE-2017-14958 Unrestricted Upload of File with Dangerous Type vulnerability in Pivotx 2.3.11
lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file.
network
low complexity
pivotx CWE-434
6.5
2017-09-30 CVE-2017-13982 Unrestricted Upload of File with Dangerous Type vulnerability in HP BSM Platform Application Performance Management System Health 9.26/9.30/9.40
A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows users to upload unrestricted files.
network
low complexity
hp CWE-434
8.8
2017-09-28 CVE-2017-14841 Unrestricted Upload of File with Dangerous Type vulnerability in Dasinfomedia Annual Maintenance Contract Management System
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.
network
low complexity
dasinfomedia CWE-434
4.0
2017-09-28 CVE-2017-14840 Unrestricted Upload of File with Dangerous Type vulnerability in Teamworktec Ticketplus
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
network
low complexity
teamworktec CWE-434
6.5
2017-09-28 CVE-2017-14839 Unrestricted Upload of File with Dangerous Type vulnerability in Teamworktec Photo Fusion
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
network
low complexity
teamworktec CWE-434
6.5
2017-09-28 CVE-2017-14838 Unrestricted Upload of File with Dangerous Type vulnerability in Teamworktec JOB Links
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
network
low complexity
teamworktec CWE-434
6.5
2017-09-28 CVE-2015-8249 Unrestricted Upload of File with Dangerous Type vulnerability in Manageengine Desktop Central 9.0
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.
network
low complexity
manageengine CWE-434
critical
10.0
2017-09-26 CVE-2017-14704 Unrestricted Upload of File with Dangerous Type vulnerability in Claydip Airbnb Clone 1.0
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/profile.
network
low complexity
claydip CWE-434
6.5