Vulnerabilities > Unrestricted Upload of File with Dangerous Type
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-10-05 | CVE-2017-1000119 | Unrestricted Upload of File with Dangerous Type vulnerability in Octobercms October 1.0.412 October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server. | 7.2 |
2017-10-04 | CVE-2017-12617 | Unrestricted Upload of File with Dangerous Type vulnerability in multiple products When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. | 8.1 |
2017-10-03 | CVE-2017-6090 | Unrestricted Upload of File with Dangerous Type vulnerability in PHPcollab 2.5/2.5.1 Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/. | 8.8 |
2017-10-02 | CVE-2017-14958 | Unrestricted Upload of File with Dangerous Type vulnerability in Pivotx 2.3.11 lib.php in PivotX 2.3.11 does not properly block uploads of dangerous file types by admin users, which allows remote PHP code execution via an upload of a .php file. | 7.2 |
2017-09-30 | CVE-2017-13982 | Unrestricted Upload of File with Dangerous Type vulnerability in HP BSM Platform Application Performance Management System Health 9.26/9.30/9.40 A directory traversal vulnerability in HPE BSM Platform Application Performance Management System Health product versions 9.26, 9.30 and 9.40, allows users to upload unrestricted files. | 8.8 |
2017-09-28 | CVE-2017-14841 | Unrestricted Upload of File with Dangerous Type vulnerability in Dasinfomedia Annual Maintenance Contract Management System Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling. | 6.5 |
2017-09-28 | CVE-2017-14840 | Unrestricted Upload of File with Dangerous Type vulnerability in Teamworktec Ticketplus TeamWork TicketPlus allows Arbitrary File Upload in updateProfile. | 8.8 |
2017-09-28 | CVE-2017-14839 | Unrestricted Upload of File with Dangerous Type vulnerability in Teamworktec Photo Fusion TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover. | 8.8 |
2017-09-28 | CVE-2017-14838 | Unrestricted Upload of File with Dangerous Type vulnerability in Teamworktec JOB Links TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange. | 8.8 |
2017-09-28 | CVE-2015-8249 | Unrestricted Upload of File with Dangerous Type vulnerability in Manageengine Desktop Central 9.0 The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter. | 9.8 |