Vulnerabilities > Unrestricted Upload of File with Dangerous Type

DATE CVE VULNERABILITY TITLE RISK
2018-03-12 CVE-2018-7562 Unrestricted Upload of File with Dangerous Type vulnerability in Glpi-Project Glpi
A remote code execution issue was discovered in GLPI through 9.2.1.
network
high complexity
glpi-project CWE-434
7.5
2018-03-09 CVE-2014-2592 Unrestricted Upload of File with Dangerous Type vulnerability in Arubanetworks web Management Portal 6.3.0.60730
Unrestricted file upload vulnerability in Aruba Web Management portal allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
network
low complexity
arubanetworks CWE-434
critical
9.8
2018-03-08 CVE-2018-1215 Unrestricted Upload of File with Dangerous Type vulnerability in Dell products
An arbitrary file upload vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.18, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.21, Dell EMC VASA Virtual Appliance versions prior to 8.4.0.514, and Dell EMC VMAX Embedded Management (eManagement) versions prior to and including 1.4 (Enginuity Release 5977.1125.1125 and earlier).
network
low complexity
dell CWE-434
8.8
2018-03-07 CVE-2016-7443 Unrestricted Upload of File with Dangerous Type vulnerability in Exponentcms Exponent CMS
Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."
network
low complexity
exponentcms CWE-434
critical
9.8
2018-03-05 CVE-2018-7665 Unrestricted Upload of File with Dangerous Type vulnerability in Clip-Bucket Clipbucket
An issue was discovered in ClipBucket before 4.0.0 Release 4902.
network
low complexity
clip-bucket CWE-434
critical
9.8
2018-03-04 CVE-2018-7567 Unrestricted Upload of File with Dangerous Type vulnerability in Otrs
In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to exploit a Blind Remote Code Execution vulnerability by loading a crafted opm file with an embedded CodeInstall element to execute a command on the server during package installation.
network
low complexity
otrs CWE-434
7.2
2018-03-01 CVE-2017-6931 Unrestricted Upload of File with Dangerous Type vulnerability in Drupal
In Drupal versions 8.4.x versions before 8.4.5 the Settings Tray module has a vulnerability that allows users to update certain data that they do not have the permissions for.
network
low complexity
drupal CWE-434
6.5
2018-02-22 CVE-2018-7316 Unrestricted Upload of File with Dangerous Type vulnerability in Christianwebministries Proclaim 9.1.1
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
network
low complexity
christianwebministries CWE-434
critical
9.8
2018-02-18 CVE-2018-7217 Unrestricted Upload of File with Dangerous Type vulnerability in Tejari Bravo Solution
In Bravo Tejari Procurement Portal, uploaded files are not properly validated by the application either on the client or the server side.
network
low complexity
tejari CWE-434
8.8
2018-02-15 CVE-2016-8515 Unrestricted Upload of File with Dangerous Type vulnerability in HP Version Control Repository Manager
A remote malicious file upload vulnerability in HPE Version Control Repository Manager (VCRM) was found.
network
low complexity
hp CWE-434
8.8